DMSniff

First seen
2019-02-01 00:00:00
Malware type
trojan
Family
Malware family
Profile updated
2026-07-07 14:58:06

Targeted industries: retail-and-hospitality media-and-entertainment

Context

DMSniff is a point-of-sale malware previously only privately sold. It has been used in breaches of small- and medium-sized businesses in the restaurant and entertainment industries. It uses a domain generation algorithm (DGA) to create lists of command-and-control domains on the fly.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Dmsniff_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Dmsniff (report)
  • flashpoint-intel.com — Dmsniff Pos Malware Actively Leveraged Target Medium Sized Businesses (report)
  • medium.com — Gazavat Expiro Dmsniff Connection And Dga Analysis 8B965Cc0221D (report)

External references