FIN7 Hackers Use the PILLOWMINT Malware to Scrape Card Data

bank account worth to hackers

The FIN7 hacking group is one of the most renowned financially motivated actors. They are the hackers responsible for the development and use of the one of the most dangerous banking Trojans, Carbanak. Of course, the group is not simply relying on old malware to run their operations – they regularly introduce new malware families to their arsenal. One of the recent additions is the PILLOWMINT, which continues to go undergo regular updates. The PILLOWMINT Malware appears to be used by the FIN7 hackers exclusively, and it does not seem to be shared with other threat actors.

The infection vector that the criminals use to deploy the PILLOWMINT is peculiar. They are relying on malicious shim databases, which could run through the Windows Application Compatibility Framework. This may allow the hackers to temporarily bypass some of the Windows security features.

What does PILLOWMINT do?

Once running, this implant will injects its code in a legitimate copy of the svchost.exe process. One of the peculiar features of this malware is its ability to log its own activity. It is likely that the criminals are fetching these logs for debugging purposes, as well as to find out how they could further optimize their attack. The primary purpose of the malware is, of course, different. It has the ability to read and scrape the computer's memory in order to look for credit card information. This is likely to imply that point-of-sale (PoS) devices are PILLOWMINT's ultimate target.

In addition to the memory scraping component, the malware has some interesting self-destruction features. The criminals can trigger a remote command to terminate the process or to force it to crash. The latter is likely to be a backup termination technique.

The FIN7 hackers seem to be regularly introducing new malware to their campaigns. Earlier in 2021, the FIN7 Cybercrime Gang introduced the Lizar Backdoor.

September 2, 2021
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.