Malware
Grateful POS
aka FrameworkPOS · SCRAPMINT · trinity
POS malware targets systems that run physical point-of-sale device and operates by inspecting the process memory for data that matches the structure of credit card data (Track1 and Track2 data), such
Grateful POS, also known as FrameworkPOS, SCRAPMINT, trinity, is a Windows malware family operated by Skeleton Spider and FIN6.
Background
This point-of-sale threat infects machines connected to physical POS terminals and scans process memory for byte patterns matching credit card data (Track1 and Track2), including the account number, expiration date, and other details encoded on a card's magnetic stripe. It exploits the window in which a freshly swiped card's primary account number (PAN) and related fields remain unencrypted in POS memory before the system routes them for authorization. Disguised as LogMein software, GratefulPOS surfaced around the autumn 2017 shopping season with a low VirusTotal detection rate, its earliest sample uploaded in November 2017. The family is believed to be tied to FrameworkPOS, malware previously implicated in several high-profile retailer breaches.
Source: Malpedia (Fraunhofer FKIE).