Labeless Part 3: How to Dump and Auto-Resolve WinAPI Calls in LockPos Point-of-Sale Malware
By
In this part we show how to automatically resolve all WinAPI calls in malicious code dump of LockPoS Point-of-Sale malware. Instead of manually reconstructing a corrupted Import Address Table we simply extract a target portion of code in the research database with all the calls present in it. We also demonstrate how to automatically propagate… Click to Read More
The post Labeless Part 3: How to Dump and Auto-Resolve WinAPI Calls in LockPos Point-of-Sale Malware appeared first on Check Point Research.
You may also like
A New Ransomware Leader Emerges as June 2026 Attack Volumes Climb Worldwide
Key takeaways Weekly cyber-attacks per organization reached 2,270 in June ...
When AI Invents the Attack: Browser-Native Ransomware
Check Point Research recently uncovered something that changes how we ...
Amazon Prime Day 2026: Bargains Begin June 23 — and So Do the Scams
When Amazon Prime Day returns on June 23–26, 2026, more ...
From Stars to Upvotes: The Fake Reputation Economy Behind a Crypto Clipboard Hijackers
Key Findings Trust is being manufactured at scale. A single ...



