{
	"id": "c9a42233-4fd6-438b-8dc9-804088197622",
	"created_at": "2026-04-06T00:18:39.770336Z",
	"updated_at": "2026-04-10T03:21:30.2247Z",
	"deleted_at": null,
	"sha1_hash": "e2b22c89f59f356cf11a3c58b569115a7ceda579",
	"title": "Threat Group Cards: A Threat Actor Encyclopedia",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 47800,
	"plain_text": "Threat Group Cards: A Threat Actor Encyclopedia\nArchived: 2026-04-05 15:04:59 UTC\nHome \u003e List all groups \u003e List all tools \u003e List all groups using tool LockPOS\n Tool: LockPOS\nNames LockPOS\nCategory Malware\nType POS malware, Credential stealer\nDescription\n(Cylance) LockPOS is a point-of-sale malware discovered in 2017 that is used to\nexfiltrate payment card data from targeted point-of-sale systems’ memory. The most\nrecent version of LockPOS examined here changed its injection technique to drop the\nmalware directly to the kernel to evade detection and bypass traditional antivirus (AV)\nhooks.\nInformation\nMalpedia AlienVault OTX Last change to this tool card: 24 May 2020\nDownload this tool card in JSON format\nAll groups using tool LockPOS\nChanged Name Country Observed\nUnknown groups\n _[ Interesting malware not linked to an actor yet ]_\n1 group listed (0 APT, 0 other, 1 unknown)\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=d309aab8-3ff4-4f80-8d7f-a1834714fac9\nPage 1 of 2\n\nSource: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=d309aab8-3ff4-4f80-8d7f-a1834714fac9\r\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=d309aab8-3ff4-4f80-8d7f-a1834714fac9\r\nPage 2 of 2\n\nUnknown groups _[ Interesting malware not linked to an actor yet ]_\n1 group listed (0 APT, 0 other, 1 unknown) \n   Page 1 of 2",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"ETDA"
	],
	"references": [
		"https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=d309aab8-3ff4-4f80-8d7f-a1834714fac9"
	],
	"report_names": [
		"listgroups.cgi?u=d309aab8-3ff4-4f80-8d7f-a1834714fac9"
	],
	"threat_actors": [],
	"ts_created_at": 1775434719,
	"ts_updated_at": 1775791290,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/e2b22c89f59f356cf11a3c58b569115a7ceda579.pdf",
		"text": "https://archive.orkl.eu/e2b22c89f59f356cf11a3c58b569115a7ceda579.txt",
		"img": "https://archive.orkl.eu/e2b22c89f59f356cf11a3c58b569115a7ceda579.jpg"
	}
}