SYMBOLCOMMON_NAMEaka. SYNONYMS
win.abaddon_pos (Back to overview)

AbaddonPOS

aka: PinkKite, TinyPOS
VTCollection    

MajorGeeks describes this malware as trying to locate credit card data by reading the memory of all processes except itself by first blacklisting its own PID using the GetCurrentProcessId API. Once that data is discovered, it sends this data back to a command and control server using a custom binary protocol instead of HTTP.

References
2021-02-15 ⋅ Medium s2wlab ⋅ Sojun Ryu
Operation SyncTrek
AbaddonPOS Azorult Clop DoppelDridex DoppelPaymer Dridex PwndLocker
2020-11-02 ⋅ One Night in Norfolk ⋅ Kevin Perlow
TinyPOS and ProLocker: An Odd Relationship
AbaddonPOS PwndLocker
2020-05-21 ⋅ VMWare Carbon Black ⋅ Jared Myers
TAU Technical Report: New Attack Combines TinyPOS With Living-off-the-Land Techniques for Scraping Credit Card Data
AbaddonPOS
2018-03-14 ⋅ Threatpost ⋅ Tom Spring
New POS Malware PinkKite Takes Flight
AbaddonPOS
2016-05-10 ⋅ Proofpoint ⋅ Darien Huss, Matthew Mesa
Setting Sights On Retail: AbaddonPOS Now Targeting Specific POS Software
AbaddonPOS TinyLoader
2015-11-11 ⋅ Proofpoint ⋅ Darien Huss
AbaddonPOS: A new point of sale threat linked to Vawtrak
AbaddonPOS TinyLoader
Yara Rules
[TLP:WHITE] win_abaddon_pos_auto (20260917 | Detects win.abaddon_pos.)
rule win_abaddon_pos_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.abaddon_pos."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.abaddon_pos"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 750a 83fb3c 7605 e9???????? }
            // n = 4, score = 200
            //   750a                 | jne                 0xc
            //   83fb3c               | cmp                 ebx, 0x3c
            //   7605                 | jbe                 7
            //   e9????????           |                     

        $sequence_1 = { 0f8455010000 8b85c8feffff 3905???????? 7502 ebd8 31db }
            // n = 6, score = 100
            //   0f8455010000         | je                  0x15b
            //   8b85c8feffff         | mov                 eax, dword ptr [ebp - 0x138]
            //   3905????????         |                     
            //   7502                 | jne                 4
            //   ebd8                 | jmp                 0xffffffda
            //   31db                 | xor                 ebx, ebx

        $sequence_2 = { eb27 8b8600010000 03860c010000 89867c010000 }
            // n = 4, score = 100
            //   eb27                 | jmp                 0x29
            //   8b8600010000         | mov                 eax, dword ptr [esi + 0x100]
            //   03860c010000         | add                 eax, dword ptr [esi + 0x10c]
            //   89867c010000         | mov                 dword ptr [esi + 0x17c], eax

        $sequence_3 = { ff45f4 eb06 43 e9???????? 68c8000000 ff15???????? }
            // n = 6, score = 100
            //   ff45f4               | inc                 dword ptr [ebp - 0xc]
            //   eb06                 | jmp                 8
            //   43                   | inc                 ebx
            //   e9????????           |                     
            //   68c8000000           | push                0xc8
            //   ff15????????         |                     

        $sequence_4 = { 8b8ec0050000 48 c7c200000000 ff15???????? 48 }
            // n = 5, score = 100
            //   8b8ec0050000         | mov                 ecx, dword ptr [esi + 0x5c0]
            //   48                   | dec                 eax
            //   c7c200000000         | mov                 edx, 0
            //   ff15????????         |                     
            //   48                   | dec                 eax

        $sequence_5 = { ebe4 50 ff15???????? 6a00 6a00 }
            // n = 5, score = 100
            //   ebe4                 | jmp                 0xffffffe6
            //   50                   | push                eax
            //   ff15????????         |                     
            //   6a00                 | push                0
            //   6a00                 | push                0

        $sequence_6 = { 7524 8b869c010000 b400 b202 f6f2 80fc00 7507 }
            // n = 7, score = 100
            //   7524                 | jne                 0x26
            //   8b869c010000         | mov                 eax, dword ptr [esi + 0x19c]
            //   b400                 | mov                 ah, 0
            //   b202                 | mov                 dl, 2
            //   f6f2                 | div                 dl
            //   80fc00               | cmp                 ah, 0
            //   7507                 | jne                 9

        $sequence_7 = { 49 c7c0???????? 49 c7c100000000 }
            // n = 4, score = 100
            //   49                   | dec                 ecx
            //   c7c0????????         |                     
            //   49                   | dec                 ecx
            //   c7c100000000         | mov                 ecx, 0

        $sequence_8 = { ff15???????? 48 83c420 48 83ec20 48 8b8ed0050000 }
            // n = 7, score = 100
            //   ff15????????         |                     
            //   48                   | dec                 eax
            //   83c420               | add                 esp, 0x20
            //   48                   | dec                 eax
            //   83ec20               | sub                 esp, 0x20
            //   48                   | dec                 eax
            //   8b8ed0050000         | mov                 ecx, dword ptr [esi + 0x5d0]

        $sequence_9 = { ff15???????? 48 83c430 48 8986c0050000 48 }
            // n = 6, score = 100
            //   ff15????????         |                     
            //   48                   | dec                 eax
            //   83c430               | add                 esp, 0x30
            //   48                   | dec                 eax
            //   8986c0050000         | mov                 dword ptr [esi + 0x5c0], eax
            //   48                   | dec                 eax

        $sequence_10 = { 48 8b8ed0050000 48 c7c200d00700 ff15???????? 48 83c420 }
            // n = 7, score = 100
            //   48                   | dec                 eax
            //   8b8ed0050000         | mov                 ecx, dword ptr [esi + 0x5d0]
            //   48                   | dec                 eax
            //   c7c200d00700         | mov                 edx, 0x7d000
            //   ff15????????         |                     
            //   48                   | dec                 eax
            //   83c420               | add                 esp, 0x20

        $sequence_11 = { 7205 e9???????? eb91 81be0c01000080cf0700 7607 }
            // n = 5, score = 100
            //   7205                 | jb                  7
            //   e9????????           |                     
            //   eb91                 | jmp                 0xffffff93
            //   81be0c01000080cf0700     | cmp    dword ptr [esi + 0x10c], 0x7cf80
            //   7607                 | jbe                 9

        $sequence_12 = { ff15???????? 48 83c420 c7437800000000 48 83ec20 }
            // n = 6, score = 100
            //   ff15????????         |                     
            //   48                   | dec                 eax
            //   83c420               | add                 esp, 0x20
            //   c7437800000000       | mov                 dword ptr [ebx + 0x78], 0
            //   48                   | dec                 eax
            //   83ec20               | sub                 esp, 0x20

        $sequence_13 = { 0396a0010000 01da 80beb001000001 7502 }
            // n = 4, score = 100
            //   0396a0010000         | add                 edx, dword ptr [esi + 0x1a0]
            //   01da                 | add                 edx, ebx
            //   80beb001000001       | cmp                 byte ptr [esi + 0x1b0], 1
            //   7502                 | jne                 4

        $sequence_14 = { 6800300000 6800100000 6a00 ff15???????? 83f800 7502 ebe5 }
            // n = 7, score = 100
            //   6800300000           | push                0x3000
            //   6800100000           | push                0x1000
            //   6a00                 | push                0
            //   ff15????????         |                     
            //   83f800               | cmp                 eax, 0
            //   7502                 | jne                 4
            //   ebe5                 | jmp                 0xffffffe7

    condition:
        7 of them and filesize < 40960
}
[TLP:WHITE] win_abaddon_pos_w0   (20180322 | AbaddonPOS)
rule win_abaddon_pos_w0 {
    meta:
        author = "Darien Huss, Proofpoint"
        description = "AbaddonPOS"
        reference = "md5,317f9c57f7983e2608d5b2f00db954ff"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.abaddon_pos"
        malpedia_version = "20180322"
        malpedia_license = "CC BY-NC-SA 4.0"
        malpedia_sharing = "TLP:WHITE"
    strings:
        $s1 = "devil_host" fullword ascii
        $s2 = "Chrome" fullword ascii
        $s3 = "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" fullword ascii
        $i1 = { 31 ?? 81 ?? 55 89 E5 8B 74 }
    condition:
        all of ($s*) or $i1
}
Download all Yara Rules