FASTCash is a malware family used to fraudulently authorize ATM cash withdrawals by compromising bank payment-switch or payment-authorization systems that process ISO 8583 financial transaction messages. Rather than infecting ATMs directly, it is deployed on backend banking infrastructure and intercepts transaction traffic inside the authorization workflow. Known variants include AIX Type 1, AIX Type 2, and a Windows version, reflecting adaptation to different payment-switch environments.
FASTCash operates by injecting into the payment-switch process and intercepting network messaging functions used to handle ISO 8583 requests and responses. It selectively inspects transaction fields such as message type and processing code, and when attacker-defined criteria are met it suppresses forwarding to the legitimate authorization application and instead generates forged approval responses. It can also fabricate balance-inquiry responses. Transactions that do not match its logic are typically passed through normally, helping the malware blend into legitimate payment traffic.
The family is tailored to target-specific implementations of ISO 8583 and banking infrastructure. Reported variants include logic for validating message origin, checking transaction attributes, applying allowlist or blacklist-style controls, and constructing fraudulent responses by copying or modifying fields from the original request. Some variants randomize returned amounts in forged withdrawal or inquiry responses. Public reporting has described FASTCash as consisting of a process injector together with malicious modules loaded into compromised payment systems.
FASTCash has been attributed to North Korean state-linked operators, particularly the Lazarus ecosystem and activity clusters such as APT38 and BeagleBoyz, in financially motivated intrusions against banks. It has been associated with large-scale ATM cash-out operations across Asia, Africa, and other regions since at least 2016. These operations require substantial operational support, including prior compromise of bank networks, access to critical payment infrastructure, detailed knowledge of the victim’s transaction-processing environment, and coordinated cash-out crews. FASTCash is notable for enabling theft from ATM networks without installing malware on the ATM endpoints themselves.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FASTCash • Malware family, intercepts ISO 8583 messages and approves them • Three types: AIX Type 1, AIX Type 2, Windows
"Financial theft operations include FASTCash, which abuses payment switches to coordinate ATM cash-outs..."
7 distinct techniques documented for this family, organized by ATT&CK tactic.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tooling used to abuse payment switch infrastructure to enable coordinated fraudulent ATM cash-outs (including a noted '2.0' evolution).
RAT and proxy/tunneling tool set associated with financial attacks.
Malware targeting bank payment authorization infrastructure, especially IBM AIX systems, by injecting into transaction-processing processes and fraudulently approving attacker-controlled ATM withdrawals.
Malware used in ATM cash-out schemes to facilitate fraudulent withdrawals from financial institutions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.