A new, advanced variant of FrameworkPoS has emerged on the scene
A new version of FrameworkPoS has been detected by security researchers at Trustwave, which carries advanced features but also exhibits some unusual activity, as we will see below.
FrameworkPoS is an old POS (Point of Sale) malware, which according to experts is allegedly responsible for the massive data breach that occurred at Home Depot during the past year, where the details of 56 million payment cards were leaked.
[alert variation=”alert-success”]Security researchers are constantly detecting new variants of this malware family, while the most recent variant detected indicates that FrameworkPoS developers are preparing to proceed with a complete overhaul of the software.[/alert]
And while some POS features , such as encoding processes, the data exfiltration mechanism, and the “memory scraping process blacklisting” feature, have remained untouched, the new version also incorporates some significant changes.
“Previous versions of FrameworkPoS install themselves as services in an attempt to hide and persist on victims’ systems,” explains Trustwave’s Eric Merritt. “This particular version uses two PowerShell scripts, which can inject either a 32-bit or a 64-bit version of the malware into memory.”
In this way, malware carriers make its detection more difficult than ever, as they do not expose the binaries on the computer's disk, which is thoroughly scanned by antivirus software when searching for new threats.
This significant change in how it operates leads us to believe that the malware is going to evolve significantly in future versions.
FrameworkPoS, version…Frankenstein
As Trustwave researchers explain, “this variant has a … Frankenstein feel,” referring to the numerous “fragments” of code that have been “stitched” together, of which very few lines of code are actually used.
This particular version of the malware appears to be under development, as its creators have not reviewed the source code to remove any dead pieces of code that are no longer used, or have been copied and pasted from previous versions of FrameworkPoS.
Furthermore, our theory that this is some intermediate version between the main versions of FrameworkPoS is also supported by an unusual behavior exhibited by the malware.
According to Trustwave, whenever the malware detects a payment card number, instead of stealing it directly, it performs a check based on a set of rules, using some credit card number filters built into its code.
This function, however, does not make much sense for a POS malware and appears to be another piece of unnecessary code left behind by the malware's creators.
However, this feature does not make the malware any less effective, and FrameworkPoS remains a dangerous threat to credit card users making purchases online.

