TINY SPIDER
According to CrowdStrike, this actor is using TinyLoader and TinyPOS, potentially buying access through Dridex infections.
TINY SPIDER uses Dridex to access networks and steals POS data with TinyLoader and TinyPOS.
TINY SPIDER is a threat actor that potentially purchases network access via Dridex infections and deploys TinyLoader and TinyPOS tools to steal financial data. They primarily target organizations in the retail and hospitality sectors, focusing on point-of-sale (POS) systems. Key TTPs include deploying the TinyPOS malware through the TinyLoader loader and scraping credit card data from RAM. Defenders should enhance email security against Dridex infections, isolate POS networks, and monitor for suspicious memory-scraping activities.
According to CrowdStrike, this actor is using TinyLoader and TinyPOS, potentially buying access through Dridex infections.
TINY SPIDER primarily targets organizations in the retail and hospitality sectors, focusing on point-of-sale (POS) systems.
TINY SPIDER uses the TinyPOS malware, deployed through the TinyLoader loader, to steal financial data. TinyPOS scrapes credit card data from RAM.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.