Tuesday, November 12, 2024
HomeMalwareTop 5 ATM Malware Families Used By Hackers to Dispense Money from...

Top 5 ATM Malware Families Used By Hackers to Dispense Money from Targeted ATMs

Published on

Malware protection

ATM-Based cyber attacks are continually evolving with much more advanced methods and functions, attackers continuously employ the number of sophisticated malware families to trick the ATMs to dispense cash.

The first ATM skimmer malware designed to launch an attack on ATMs was spotted 10 years before. From the time of discovery, it has evolved to include several different families and different actors behind them.

ATM-based malware can cause significant damage to end users; financial institutions, and targeted banks.

- Advertisement - SIEM as a Service

“Over the past 10 years, we have seen a steady increase in the number of ATM malware samples discovered. Still, the number of discovered samples is minimal compared to almost any other malware category,” Talos reported.

Based on the functions, ATM-based malware classified into virtual skimmers and cash dispensers. The Skimmers card data, transaction details, and PINs, whereas the Cash-dispensing malware is used by attackers to dispense cash from ATMs.

The generic framework used by ATM developers is CEN/XFS framework, which allows them to compile and run the code regardless of the ATM model or manufacturer.

ATMs are not available over the internet they will communicate to bank through special channels; however, they will be connected to the internal networks for administration & maintenance purposes, certain malware takes advantage of that by compromising the internal network first.

Top ATM Malware Families
Image Credits: Talos

Top 5 ATM Malware Families

Ploutus

Ploutus malware used by several criminals to empty ATMs through an external keyboard attached to the machine or via SMS message.

The malware was observed since November 2016; it is a standard ATM-dispensing malware; attackers use this to empty ATM without a card.

Alice

Alice malware first detected in November 2016; it will simply empty the safe of ATMs. Alice directly connects with CurrencyDispenser1, upon entering correct PIN it opens operator panel which shows the cassettes were money loaded.

Cutlet

The malware sold in underground hacking forums since 2016, it is a self-paced where the threat actors provide manuals, details such as the required equipment, targeted ATMs models, as well as tips and tricks for the malware’s operation.

This type of malware does not affect bank customers directly; it is intended for the theft of cash from specific vendor ATMs.

Tyupkin

The Tyupkin malware is active since 2014, and it targets Eastern European countries. It is a timely malware to be operated on specific periods.

Attackers need to gain physical access to the ATM to infect them with Tyupkin malware, once the machine infected it disables all the network connections, even if the administrators spotted the suspicious activity it is not possible to shut down.

Skimer

It is the first skimmer malware designed to steal bank card numbers and details of the account and owner details stored on the magnetic stripe attached to the real payment terminals so that they can harvest data from every person that swipes their cards.

Scammers place skimmer that includes a camera, over the built-in customer-facing security camera in ATMs and angles them toward ATM PIN pad to record the user’s PIN.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep yourself updated.

Other Malwares

Malicious Hackers Steal Money From ATM by Connecting Laptop with ATM Cash Dispenser

Most of the ATM’s Around the World Can be Hacked Under 30 Minutes

ATMJackpot – New Malware Steal Your Money From ATM using ATM Jackpotting Technique

Now Anyone Can Buy New ATM-based Malware In Darkweb and Get All Money From ATM Anonymously

ATM Robber Malware Turns ATM into Slot Machine to Dispense Cash Automatically

Malicious Hackers Selling Malware’s Targeting Bitcoin ATMs in the Dark Web Forums

Malware Called “ATMii” allows Hackers to Dispense all the Cash from the ATM

A Fileless Malware Called “ATMitch” Attack The ATM machines Remotely and Delete The Attack Evidence

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

10 Best DNS Management Tools – 2025

Best DNS Management Tools play a crucial role in efficiently managing domain names and...

Sweet Security Announces Availability of its Cloud Native Detection & Response Platform on the AWS Marketplace

Customers can now easily integrate Sweet’s runtime detection and response platform into their AWS...

Researchers Detailed Credential Abuse Cycle

Cybercriminals exploit leaked credentials, obtained through various means, to compromise systems and data, enabling...

New Android Malware SpyAgent Taking Screenshots Of User’s Devices

SpyAgent, a newly discovered Android malware, leverages OCR technology to extract cryptocurrency recovery phrases...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

10 Best DNS Management Tools – 2025

Best DNS Management Tools play a crucial role in efficiently managing domain names and...

New Android Malware SpyAgent Taking Screenshots Of User’s Devices

SpyAgent, a newly discovered Android malware, leverages OCR technology to extract cryptocurrency recovery phrases...

HookBot Malware Use Overlay Attacks Impersonate As Popular Brands To Steal Data

The HookBot malware family employs overlay attacks to trick users into revealing sensitive information...