FastPOS, discovered in June 2016, is distributed via file sharing, direct file transfer via Virtual Network Computing (VNC), or links directing victims to a compromised website. This variant transmits stolen data to the attacker’s C2 server quickly and in real time, instead of intermittently transmitting locally stored data.

