FrameworkPOS

MITRE ATT&CK: S0503 View on attack.mitre.org

Aliases: Trinity, FrameworkPOS, SCRAPMINT, trinity

First seen
2014-12-01 00:00:00
Malware type
trojan
Family
Malware family
Profile updated
2026-07-07 12:48:42

Targeted industries: retail-and-hospitality

Context

FrameworkPOS is a point of sale (POS) malware used by FIN6 to steal payment card data from sytems that run physical POS devices.

Detection coverage

  • 31 Sigma rules

Malware & tools used

  • Data from Local System (attack-pattern)
  • Exfiltration Over Alternative Protocol (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Process Discovery (attack-pattern)
  • Archive via Custom Method (attack-pattern)

Used by threat actors

  • FIN6 (threat-actor)

Reports & references

  • Mandiant — Rpt Fin6 (report)
  • secureworks.com — Gold Franklin (report)
  • pwc.co.uk — Cyber Threats 2019 Retrospect (report)
  • ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
  • Mandiant — Rpt M Trends 2020 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Grateful Pos (report)
  • norfolkinfosec.com — Pos Malware Used At Fuel Pumps (report)
  • community.rsa.com — Gratefulpos Credit Card Stealing Malware Just In Time For The Shopping Season (report)
  • vkremez.com — Lets Learn Reversing Grateful Point Of (report)
  • usa.visa.com — Cybercrime Groups Targeting Fuel Dispenser Merchants (report)
  • redcanary.com — Frameworkpos And The Adequate Persistent Threat (report)
  • MITRE ATT&CK — S0503 (report)
  • labs.sentinelone.com — Fin6 Frameworkpos Point Of Sale Malware Analysis Internals 2 (report)

External references