BlackPOS

Aliases: Kaptoxa, MMon, POSWDS, Reedum

Malware type
credential-stealer
Family
Malware family
Last IoC activity
2026-04-27 00:22:25
Profile updated
2026-07-07 13:52:13

Targeted industries: retail-and-hospitality

Context

BlackPOS infects computers running on Windows that have credit card readers connected to them and are part of a POS system. POS system computers can be easily infected if they do not have the most up to date operating systems and antivirus programs to prevent security breaches or if the computer database systems have weak administration login credentials.

Detection coverage

  • 2 YARA rules

Detection rules

  • MALPEDIA_Win_Mmon_Auto (yara-rule)
  • MALPEDIA_Win_Blackpos_Auto (yara-rule)

Reports & references

  • web.archive.org — Globalthreatintelreport (report)
  • Trend Micro — Operation Black Atlas Endangers In Store Card Payments And Smbs Worldwide Switches Between Blackpos And Other Tools (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Blackpos (report)
  • usa.visa.com — New Pos Malware Samples (report)
  • Trend Micro — New Blackpos Malware Emerges In The Wild Targets Retail Accounts (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Mmon (report)
  • reversing.fun — Mmon (report)

External references