{
	"id": "cfe9f690-3320-4df5-a636-441ea962f927",
	"created_at": "2026-04-06T00:16:17.557487Z",
	"updated_at": "2026-04-10T03:21:17.139763Z",
	"deleted_at": null,
	"sha1_hash": "5b5765fde3f3ddab8d51a06dee450b6ab57e5aae",
	"title": "Threat Group Cards: A Threat Actor Encyclopedia",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 48207,
	"plain_text": "Threat Group Cards: A Threat Actor Encyclopedia\nArchived: 2026-04-05 16:22:03 UTC\nHome \u003e List all groups \u003e List all tools \u003e List all groups using tool MalumPOS\n Tool: MalumPOS\nNames MalumPOS\nCategory Malware\nType POS malware, Credential stealer\nDescription\n(Trend Micro) We first discovered MalumPoS, a new attack tool that threat actors can\nreconfigure to breach any PoS system they wish to target. Currently, it is designed to\ncollect data from PoS systems running on Oracle® MICROS®, a platform popularly used\nin the hospitality, food and beverage, and retail industries.\nMalumPoS was designed to be configurable. This means that in the future, the threat actor\ncan change or add other processes or targets. He can, for example, configure MalumPoS\nto include Radiant or NCR Counterpoint PoS systems to its target list. With that inclusion,\ncompanies running on those systems will also be at risk.\nInformation\nMalpedia AlienVault OTX Last change to this tool card: 24 May 2020\nDownload this tool card in JSON format\nAll groups using tool MalumPOS\nChanged Name Country Observed\nUnknown groups\n _[ Interesting malware not linked to an actor yet ]_\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=51dce14d-10bd-4d7b-ba54-bacf548b739d\nPage 1 of 2\n\n1 group listed (0 APT, 0 other, 1 unknown)\r\nSource: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=51dce14d-10bd-4d7b-ba54-bacf548b739d\r\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=51dce14d-10bd-4d7b-ba54-bacf548b739d\r\nPage 2 of 2",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"ETDA"
	],
	"references": [
		"https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=51dce14d-10bd-4d7b-ba54-bacf548b739d"
	],
	"report_names": [
		"listgroups.cgi?u=51dce14d-10bd-4d7b-ba54-bacf548b739d"
	],
	"threat_actors": [],
	"ts_created_at": 1775434577,
	"ts_updated_at": 1775791277,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/5b5765fde3f3ddab8d51a06dee450b6ab57e5aae.pdf",
		"text": "https://archive.orkl.eu/5b5765fde3f3ddab8d51a06dee450b6ab57e5aae.txt",
		"img": "https://archive.orkl.eu/5b5765fde3f3ddab8d51a06dee450b6ab57e5aae.jpg"
	}
}