Skip to content

Malware

PILLOWMINT

According to FireEye, PILLOWMINT is a Point-of-Sale malware tool used to scrape track 1 and track 2 payment card data from memory.

PILLOWMINT is a Windows malware family operated by Anunak.

Background

FireEye reports that PILLOWMINT is a Point-of-Sale malware tool designed to harvest track 1 and track 2 payment card data from memory. The captured card data is encrypted and kept in the registry as well as stored in plaintext within a file (T1074: Data Staged). It also offers backdoor features such as running processes, downloading and executing files (T1105: Remote File Copy), and downloading and injecting DLLs (T1055: Process Injection). PILLOWMINT talks to its command and control (C2) server over HTTP using AES-encrypted messages (T1071: Standard Application Layer Protocol; T1032: Standard Cryptographic Protocol).


Source: Malpedia (Fraunhofer FKIE).