AbaddonPOS
Aliases: PinkKite, TinyPOS
- First seen
- 2015-07-01 00:00:00
- Malware type
- credential-stealer
- Family
- Malware family
- Profile updated
- 2026-07-07 13:45:38
Targeted industries: retail-and-hospitality
Context
MajorGeeks describes this malware as trying to locate credit card data by reading the memory of all processes except itself by first blacklisting its own PID using the GetCurrentProcessId API. Once that data is discovered, it sends this data back to a command and control server using a custom binary protocol instead of HTTP.
Reports & references
- medium.com — Operation Synctrek E5013Df8D167 (report)
- norfolkinfosec.com — Tinypos And Prolocker An Odd Relationship (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Abaddon Pos (report)
- proofpoint.com — Abaddonpos A New Point Of Sale Threat Linked To Vawtrak (report)
- carbonblack.com — Tau Technical Report New Attack Combines Tinypos With Living Off The Land Techniques For Scraping Credit Card Data (report)
- proofpoint.com — Abaddonpos Now Targeting Specific Pos Software (report)
- threatpost.com — 130428 (report)