Also known as: Trinity
Enhanced Description
FrameworkPOS is a point‑of‑sale (POS) malware that was first disclosed in September 2019 and has since been linked to the financially motivated threat actor FIN6. The malware infiltrates retailers by compromising the POS hardware or software, intercepting unencrypted transaction data before it reaches the payment gateway. Its stealthy operation relies on process injection and sophisticated data staging to evade detection while maintaining persistence on infected systems. Once deployed, FrameworkPOS captures cardholder information—such as credit‑card numbers, expiry dates, and CVVs—from POS terminals and stores this data locally. The malware then encrypts the payload and exfiltrates it over an outbound HTTPS channel, typically routed through command‑and‑control servers owned by FIN6. The stolen credential set can be sold on secondary markets or used to conduct large‑scale card‑present fraud, resulting in significant financial losses for affected merchants. The combination of targeting high‑traffic retail environments and leveraging a sophisticated supply‑chain approach has made FrameworkPOS one of the most financially lucrative POS threats documented to date. Its continued operation underscores the importance of timely patching, rigorous monitoring of POS firmware integrity, and adherence to PCI DSS requirements for detecting unauthorized data extraction.
FrameworkPOS is a point of sale (POS) malware used by FIN6 to steal payment card data from sytems that run physical POS devices.(Citation: SentinelOne FrameworkPOS September 2019)