Skip to content

Malware

ModPipe

ModPipe is point-of-sale (POS) malware capable of accessing sensitive information stored in devices running ORACLE MICROS Restaurant Enterprise Series (RES) 3700 POS – a management software suite used

ModPipe is a Windows malware family.

Background

ModPipe is point-of-sale (POS) malware that can reach sensitive data on systems running ORACLE MICROS Restaurant Enterprise Series (RES) 3700 POS, a management suite deployed across hundreds of thousands of bars, restaurants, hotels, and other hospitality businesses worldwide. It is built on a modular design pairing core components with downloadable modules, one of which — called GetMicInfo — holds an algorithm that recovers database passwords by decrypting them from Windows registry values. Those stolen credentials give the operators access to the database, including assorted definitions and configuration, status tables, and details of POS transactions.


Source: Malpedia (Fraunhofer FKIE).