FrameworkPOS
MITRE ATT&CK: S0503 View on attack.mitre.org
Aliases: Trinity, FrameworkPOS, SCRAPMINT, trinity
- First seen
- 2014-12-01 00:00:00
- Malware type
- trojan
- Family
- Malware family
- Profile updated
- 2026-07-07 12:48:42
Targeted industries: retail-and-hospitality
Context
FrameworkPOS is a point of sale (POS) malware used by FIN6 to steal payment card data from sytems that run physical POS devices.
Detection coverage
- 31 Sigma rules
Malware & tools used
- Data from Local System (attack-pattern)
- Exfiltration Over Alternative Protocol (attack-pattern)
- Local Data Staging (attack-pattern)
- Process Discovery (attack-pattern)
- Archive via Custom Method (attack-pattern)
Used by threat actors
- FIN6 (threat-actor)
Reports & references
- Mandiant — Rpt Fin6 (report)
- secureworks.com — Gold Franklin (report)
- pwc.co.uk — Cyber Threats 2019 Retrospect (report)
- ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
- Mandiant — Rpt M Trends 2020 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Grateful Pos (report)
- norfolkinfosec.com — Pos Malware Used At Fuel Pumps (report)
- community.rsa.com — Gratefulpos Credit Card Stealing Malware Just In Time For The Shopping Season (report)
- vkremez.com — Lets Learn Reversing Grateful Point Of (report)
- usa.visa.com — Cybercrime Groups Targeting Fuel Dispenser Merchants (report)
- redcanary.com — Frameworkpos And The Adequate Persistent Threat (report)
- MITRE ATT&CK — S0503 (report)
- labs.sentinelone.com — Fin6 Frameworkpos Point Of Sale Malware Analysis Internals 2 (report)