Daily Dark Web
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
Daily Dark Web
No Result
View All Result
Home DarkWeb News & Services

New POS Malware “ShadowPOS” Advertised in DarkWeb Forum

August 16, 2024
Reading Time: 2 mins read
New POS Malware “ShadowPOS” Advertised in DarkWeb Forum

A threat actor recently introduced a new Point of Sale (POS) malware called “ShadowPOS” on a well-known cybercrime forum. Still under development, the malware is marketed as an advanced tool designed to infiltrate POS systems, steal unencrypted credit card data, and send it to a command and control (C2) server.

Stealth and Persistence Features

The creator of ShadowPOS describes it as both highly persistent and stealthy. It scans memory at regular intervals and uploads stolen data to its C2 server. By running as a single-threaded process, the malware minimizes system resource usage, making it harder to detect.

Advanced Scanning Capabilities

ShadowPOS uses a complex algorithm that efficiently locates and verifies card data. It relies on Google’s RE2 regular expressions engine to perform high-speed memory scanning across all processes on targeted Windows-based POS systems. Unlike other POS malware, ShadowPOS scans all running processes on a terminal, significantly increasing its chances of success.

Command & Control Panel

The developer is also working on a Command & Control panel, which will allow users to manage and query stolen card data. This panel aims to streamline inventory management for those looking to sell or use the compromised information.

Exclusive Pre-Sale Offer

The threat actor is offering ShadowPOS for pre-sale with a promise of exclusivity. If purchased, the malware will not be sold as a service to others. The seller also offers to customize the malware according to the buyer’s needs.

Compliance with Forum Rules

The seller has pre-approved the post with the forum’s staff to ensure it complies with the site’s rules, which prohibit the sale of credit card information and ransomware-related tools. The seller emphasizes that the malware is not intended for ransomware attacks and does not come with any stolen card data.

 

The introduction of ShadowPOS highlights the ongoing evolution of cyber threats targeting businesses. Organizations must strengthen their security measures, including the encryption of card data and regular monitoring for unusual activity, to mitigate the risks posed by this and similar malware.

Tags: Credit CardmalwarePOSShadowPOSShopping
ShareTweet

Related Posts

BreachForums Announces VECT Partnership and Security Updates
DarkWeb News & Services

BreachForums Announces VECT Partnership and Security Updates

April 16, 2026
ShinyHunters Telegram Update Claims Second Leader Arrested
DarkWeb News & Services

ShinyHunters Telegram Update Claims Second Leader Arrested

February 5, 2026
INC Ransomware Breaches Wall Street English – 3.5TB Data Leaked
DarkWeb News & Services

INC Ransomware Breaches Wall Street English – 3.5TB Data Leaked

December 25, 2025
SLSH Announces Return and Teases New Website for November 24
DarkWeb News & Services

SLSH Announces Return and Teases New Website for November 24

November 21, 2025
Operation Endgame Takedown Hits Rhadamanthys and VenomRAT
DarkWeb News & Services

Operation Endgame Takedown Hits Rhadamanthys and VenomRAT

November 13, 2025
Exclusive: Everest Ransomware Group Interview on Collins Aerospace Breach
DarkWeb News & Services

Exclusive: Everest Ransomware Group Interview on Collins Aerospace Breach

November 6, 2025
Next Post
Threat Actor Claims to Sell Data of Over 1.2 Billion China Mobile Users, Including Sensitive IMEI Information

Threat Actor Claims to Sell Data of Over 1.2 Billion China Mobile Users, Including Sensitive IMEI Information

Threat Actor Allegedly Selling Network Access to Corporations, Prices Range Up to $3,000

Threat Actor Allegedly Selling Network Access to Corporations, Prices Range Up to $3,000

Recommended Stories

Mad Liberator Added Logistics Company YCH as Their New Victim

Mad Liberator Added Logistics Company YCH as Their New Victim

September 4, 2024
Alleged Sale of Georgian Government Email Access Surfaces on Dark Web

Alleged Sale of Georgian Government Email Access Surfaces on Dark Web

March 4, 2025
Alleged Data Breach at Breitling.com Exposes Sensitive Customer Information

Alleged Data Breach at Breitling.com Exposes Sensitive Customer Information

December 12, 2024

Popular Stories

  • SudamericaData Breach Exposes Over 1TB of Argentine Records

    SudamericaData Breach Exposes Over 1TB of Argentine Records

    0 shares
    Share 0 Tweet 0
  • Threat Actor Claims Sale of Dell Database Containing 49 Million Customer Records

    0 shares
    Share 0 Tweet 0
  • SUUMO, CHINTAI, At Home, HOME’S Suffer Data Breach

    0 shares
    Share 0 Tweet 0
  • Financial Tech Giant SilverLake Axis Allegedly Breached – 423GB of Data for Sale

    0 shares
    Share 0 Tweet 0
  • Telekom Serbia Investigates Leak of 160,000 Customer Records

    0 shares
    Share 0 Tweet 0
Daily Dark Web

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

No Result
View All Result
  • About Us
  • Home
  • Newsletter
  • Privacy Policy

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?