logo

Treasure trove. Alive and well point-of-sale malware

ID: 8be8d218-d27b-5194-b84d-56690b25d787

STIX ID: report--8be8d218-d27b-5194-b84d-56690b25d787

Feed Name: Group-IB Blog

Threat Score
75/100

Date Published: 2022-10-24

Date Updated: 2026-04-27

...
...

Group-IB discovered and analyzed a command-and-control server hosting administrative panels for MajikPOS and Treasure Hunter POS RAM-scraping malware, recovering roughly 167,000 compromised payment card dumps (predominantly US-issued) and identifying infected POS devices, actor tradecraft (VNC/RDP brute-force, RAM scraping), and actionable IOCs; the report quantifies potential underground sale value (~$3.34M), maps geographic distribution, and provides mitigations and detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.