SYMBOLCOMMON_NAMEaka. SYNONYMS
win.blackpos (Back to overview)

BlackPOS

aka: Kaptoxa, MMon, POSWDS, Reedum
VTCollection    

BlackPOS infects computers running on Windows that have credit card readers connected to them and are part of a POS system. POS system computers can be easily infected if they do not have the most up to date operating systems and antivirus programs to prevent security breaches or if the computer database systems have weak administration login credentials.

References
2020-09-25 ⋅ VISA ⋅ Visa Security Alert
Visa Security Alert: New Malware Samples identified in Point-of-Sale Compromises
BlackPOS pwnpos rtpos
2015-12-01 ⋅ Trend Micro ⋅ Erika Mendoza, Jay Yaneza
Operation Black Atlas Endangers In-Store Card Payments and SMBs Worldwide; Switches between BlackPOS and Other Tools
Alina POS BlackPOS Kronos NewPosThings
2015-02-06 ⋅ CrowdStrike ⋅ CrowdStrike
CrowdStrike Global Threat Intel Report 2014
BlackPOS CryptoLocker Derusbi Elise Enfal EvilGrab Gameover P2P HttpBrowser MedusaHTTP Mirage Naikon NetTraveler pirpi PlugX Poison Ivy Sakula RAT Sinowal sykipot taidoor
2014-08-29 ⋅ Trend Micro ⋅ Rhena Inocencio
New BlackPOS Malware Emerges in the Wild, Targets Retail Accounts
BlackPOS
Yara Rules
[TLP:WHITE] win_blackpos_auto (20260917 | Detects win.blackpos.)
rule win_blackpos_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.blackpos."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blackpos"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 6a02 83c6f2 68???????? 56 e8???????? }
            // n = 5, score = 100
            //   6a02                 | push                2
            //   83c6f2               | add                 esi, -0xe
            //   68????????           |                     
            //   56                   | push                esi
            //   e8????????           |                     

        $sequence_1 = { 68b80b0000 6a01 33c9 51 }
            // n = 4, score = 100
            //   68b80b0000           | push                0xbb8
            //   6a01                 | push                1
            //   33c9                 | xor                 ecx, ecx
            //   51                   | push                ecx

        $sequence_2 = { 56 57 33ff ffb7b0f84100 ff15???????? 8987b0f84100 83c704 }
            // n = 7, score = 100
            //   56                   | push                esi
            //   57                   | push                edi
            //   33ff                 | xor                 edi, edi
            //   ffb7b0f84100         | push                dword ptr [edi + 0x41f8b0]
            //   ff15????????         |                     
            //   8987b0f84100         | mov                 dword ptr [edi + 0x41f8b0], eax
            //   83c704               | add                 edi, 4

        $sequence_3 = { c745f44d4d4d4d c745f84d4d0000 e8???????? 8d45b4 50 e8???????? }
            // n = 6, score = 100
            //   c745f44d4d4d4d       | mov                 dword ptr [ebp - 0xc], 0x4d4d4d4d
            //   c745f84d4d0000       | mov                 dword ptr [ebp - 8], 0x4d4d
            //   e8????????           |                     
            //   8d45b4               | lea                 eax, [ebp - 0x4c]
            //   50                   | push                eax
            //   e8????????           |                     

        $sequence_4 = { c7430801000000 e8???????? 6a06 89430c 8d4310 8d8994f34100 5a }
            // n = 7, score = 100
            //   c7430801000000       | mov                 dword ptr [ebx + 8], 1
            //   e8????????           |                     
            //   6a06                 | push                6
            //   89430c               | mov                 dword ptr [ebx + 0xc], eax
            //   8d4310               | lea                 eax, [ebx + 0x10]
            //   8d8994f34100         | lea                 ecx, [ecx + 0x41f394]
            //   5a                   | pop                 edx

        $sequence_5 = { 83c414 ff05???????? 6a05 e8???????? 59 8b4dfc 5f }
            // n = 7, score = 100
            //   83c414               | add                 esp, 0x14
            //   ff05????????         |                     
            //   6a05                 | push                5
            //   e8????????           |                     
            //   59                   | pop                 ecx
            //   8b4dfc               | mov                 ecx, dword ptr [ebp - 4]
            //   5f                   | pop                 edi

        $sequence_6 = { 47 3bbddcfbffff 7cc9 6a02 8d85e4fbffff 68???????? 50 }
            // n = 7, score = 100
            //   47                   | inc                 edi
            //   3bbddcfbffff         | cmp                 edi, dword ptr [ebp - 0x424]
            //   7cc9                 | jl                  0xffffffcb
            //   6a02                 | push                2
            //   8d85e4fbffff         | lea                 eax, [ebp - 0x41c]
            //   68????????           |                     
            //   50                   | push                eax

        $sequence_7 = { 8bc8 83e01f c1f905 8b0c8d60c45800 c1e006 8d440104 800820 }
            // n = 7, score = 100
            //   8bc8                 | mov                 ecx, eax
            //   83e01f               | and                 eax, 0x1f
            //   c1f905               | sar                 ecx, 5
            //   8b0c8d60c45800       | mov                 ecx, dword ptr [ecx*4 + 0x58c460]
            //   c1e006               | shl                 eax, 6
            //   8d440104             | lea                 eax, [ecx + eax + 4]
            //   800820               | or                  byte ptr [eax], 0x20

        $sequence_8 = { 8d4dec e8???????? 8975f8 897dfc c745ecf0824100 }
            // n = 5, score = 100
            //   8d4dec               | lea                 ecx, [ebp - 0x14]
            //   e8????????           |                     
            //   8975f8               | mov                 dword ptr [ebp - 8], esi
            //   897dfc               | mov                 dword ptr [ebp - 4], edi
            //   c745ecf0824100       | mov                 dword ptr [ebp - 0x14], 0x4182f0

        $sequence_9 = { 53 56 891d???????? e8???????? 83c40c 80bda8f4ffff01 }
            // n = 6, score = 100
            //   53                   | push                ebx
            //   56                   | push                esi
            //   891d????????         |                     
            //   e8????????           |                     
            //   83c40c               | add                 esp, 0xc
            //   80bda8f4ffff01       | cmp                 byte ptr [ebp - 0xb58], 1

    condition:
        7 of them and filesize < 3293184
}
Download all Yara Rules