Ploutus is a Windows-based ATM jackpotting malware family first identified in Mexico in 2013. It compromises ATM endpoints and abuses ATM middleware, including eXtensions for Financial Services (XFS), to issue unauthorized commands to cash-dispensing modules. This enables attackers to force cash withdrawals without a payment card, customer account, or bank authorization. Early variants targeted NCR ATMs, while later variants expanded compatibility through support for multivendor ATM frameworks such as KAL Kalignite and have been used against multiple ATM manufacturers.
Ploutus infections have commonly required physical access to ATM internals. Operators have installed it by accessing internal storage or local interfaces, including modifying an ATM hard drive, replacing it with a prepared drive, or using attached devices. Historical variants used an external keyboard for operator control; Ploutus.B also supported SMS-triggered cash-out operations through a phone connected to the compromised ATM. Ploutus incorporates operator authentication codes, and some variants include remote-management and anti-forensic capabilities, including self-removal after dispensing cash.
The malware has been associated with ATM cash-out campaigns in Mexico, Latin America, and the United States. U.S. law-enforcement reporting has identified Ploutus as a malware family used in recent large-scale jackpotting activity, including campaigns alleged to involve crews connected to the Venezuela-origin Tren de Aragua criminal organization. Attribution of the original development of Ploutus to specific individuals or that organization has not been conclusively established. Ploutus primarily targets Windows-based ATM environments and financial institutions operating vulnerable or physically accessible cash machines.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“TdA typically uses the malware named Ploutus.” The article describes attackers physically installing malware on ATMs, remotely activating it to bypass ATM security systems, and issuing dispense commands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
“Attackers frequently exploit generic service keys, outdated operating systems or unsecured USB ports before installing malware that bypasses bank authorisation controls,” he added.
“Attackers frequently exploit generic service keys, outdated operating systems or unsecured USB ports before installing malware that bypasses bank authorisation controls,” he added.
“Custom services… HKLM\SYSTEM\CurrentControlSet\Services\ … Services pointing to non-standard install paths… generic or deceptive names: ATM Service, Dispenser Service”
“Attackers frequently exploit generic service keys, outdated operating systems or unsecured USB ports before installing malware that bypasses bank authorisation controls,” he added.
“Custom services… HKLM\SYSTEM\CurrentControlSet\Services\ … Services pointing to non-standard install paths… generic or deceptive names: ATM Service, Dispenser Service”
“Services running with generic or deceptive names: ATM Service, Dispenser Service” and “Executable files not expected on the hard drive… NCRApp.exe… WinMonitor.exe…”
“Possible logged attack example… Logs cleared 1102” and “Generating Event ID 1102, Security log cleared”
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
42 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ATM jackpotting malware used in attacks linked to Tren de Aragua. Following physical installation on targeted ATMs, it can be remotely activated to bypass security controls and force cash dispensing.
ATM jackpotting malware designed to compel automated teller machines to dispense cash without debiting accounts. In this scheme, it was physically installed on ATM hard drives via Raspberry Pi devices and included a self-delete capability to erase traces after cash dispensing.
An advanced ATM jackpotting malware family that enables criminals to dispense cash from compromised ATMs. It was initially observed against ATMs in Mexico in 2013 and can be operated using an external keyboard or SMS commands.
ATM malware used for jackpotting attacks to trigger unauthorized cash dispensing from ATMs.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.