Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Sichere ProgrammierungWhat's one small dev habit that made a big difference for you?(20.09.2026 um 08:10 Uhr)
Sichere ProgrammierungI Built Shree AI OS — A Deterministic AI Runtime for Java 21(20.09.2026 um 08:20 Uhr)
Sichere ProgrammierungSaddle-Stitch PDF Imposition: Why Page Counts Must Be Multiples of 4(20.09.2026 um 08:20 Uhr)
Sichere Programmierungfvpn - Lightweight CLI VPN Client for FastestVPN on Linux(20.09.2026 um 08:20 Uhr)
Sichere ProgrammierungMy Monitoring Cron Never Ran Once. crontab -l Showed It Fine.(20.09.2026 um 08:49 Uhr)
IT Security ToolsBrowserBox v19.0.3(20.09.2026 um 08:30 Uhr)
IT Security NachrichtenHackerangriff auf Smart Locks: Diese Schwachstellen sollte jeder kennen(20.09.2026 um 07:00 Uhr)
Sichere ProgrammierungWhat's one small dev habit that made a big difference for you?(20.09.2026 um 08:10 Uhr)
Sichere ProgrammierungI Built Shree AI OS — A Deterministic AI Runtime for Java 21(20.09.2026 um 08:20 Uhr)
Sichere ProgrammierungSaddle-Stitch PDF Imposition: Why Page Counts Must Be Multiples of 4(20.09.2026 um 08:20 Uhr)
Sichere Programmierungfvpn - Lightweight CLI VPN Client for FastestVPN on Linux(20.09.2026 um 08:20 Uhr)
Sichere ProgrammierungMy Monitoring Cron Never Ran Once. crontab -l Showed It Fine.(20.09.2026 um 08:49 Uhr)
IT Security ToolsBrowserBox v19.0.3(20.09.2026 um 08:30 Uhr)
IT Security NachrichtenHackerangriff auf Smart Locks: Diese Schwachstellen sollte jeder kennen(20.09.2026 um 07:00 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

Researchers find new POS malwares

Researchers have now discovered two new and different strains of point of sale (POS) malware including one that has gone largely undetected for the past five years.

Researchers have described Cherry Picker, a set of PoS malware which in one form or another has been targeting businesses that sell food and beverage since 2011.

The malware is reportedly said to be used in a recent breach at an unidentified U.S. restaurant chain.
The new form of memory-scraping POS malware has become a threat for retailers.

The Federal Bureau of Investigation (FBI) has released a warning to keep guards against the malware as it can infect any Windows-based POS network and can encrypt the data stolen, making detection difficult.
Researchers with Trustwave have noticed some basic elements of the malware back in 2011 but the malware has gone through three iterations in the years since, adding new configuration files, ways to scrape memory, and remain persistent. 

The malware has managed to stay covert since many years by using a combination of configuration files, encryption, obfuscation, and command line arguments. 

During his research Eric Merritt, the primary researcher who observed the malware found a file on a system infected by Cherry Picker that helped cover the malware’s tracks all these years, too. The file contains hardcoded paths to the malware, exfiltration files, and legitimate files on the system. A special “custom shredder function” in the code goes ahead and overwrites the file multiple times with 00’s, FF’s, and “cryptographic junk” before going on to shred a list of malware and exfiltration file locations, and the executable itself. From there, the code removes any remaining traces of the PoS malware.

With this reaserchers have also discovered the existence of another type of POS malware known as Abaddon. This is relatively newer to Cherry Picker.

Vawtrak, a banking Trojan, downloaded TinyLoader, a downloader which in turn, downloaded another downloader which downloaded shellcode that turned into Abaddon.

“AbbadonPOS appears to have features for anti-analysis, code obfuscation, persistence, location of credit card data, and a custom protocol for exfiltrating data. Much like malware as a general category, the sophistication of this new malware over prior malware continues to increase,” said Kevin Epstein, Vice President of Threat Operations at the firm.

In addition, security firm Trend Micro is warning of a new malware called Malum POS which targets the Oracle Micros POS system.

Attackers are going to have several choices when it comes to POS malware this season.
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Researchers find new POS malwares

Thematisch verwandte Begriffe: Researchers, find, malwares · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-93987 | rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerabi…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick