LusyPOS Malware Detection

Critical Nessus Plugin ID 80457


Nessus detected a malicious process on the remote host.


The remote host is running LusyPOS, a point-of-sale (POS) malware that uses memory scraping techniques and the Tor network to exfiltrate data.


Remove the infection or restore the system from a known set of good backups.

See Also

Plugin Details

Severity: Critical

ID: 80457

File Name: lusypos_detect.nbin

Version: 1.125

Type: remote

Family: Backdoors

Published: 2014/01/12

Modified: 2018/12/06

Dependencies: 70329, 70621

Risk Information

Risk Factor: Critical

CVSS v2.0

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/o:microsoft:windows

Vulnerability Publication Date: 2014/12/01