Blog | G5 Cyber Security

New Malware Dubbed LockPos Introduces New Injection Technique To Avoid Detection

Security Researchers from Cyberbit have discovered a new malware injection technique being used by a variant of Flokibot malware named LockPoS. LockPos reads the memory of currently running processes on the system, searching for data that looks like credit card information and then sends them to the C&C. The malware does not call the routines from ntdll to avoid anti-virus detection, instead, it maps routines on the disk to its own virtual address space. By doing so the malware maintains a clean copy of dll that is not detected.”]

Source: https://securityaffairs.co/wordpress/67601/breaking-news/lockpos-pos-malware-injection.html

Exit mobile version