Ploutus is a sophisticated ATM jackpotting malware family first identified in Mexico in 2013 and widely regarded as one of the most prominent and extensively observed ATM cash-out malware families. It targets Windows-based automated teller machines by abusing ATM middleware, especially the eXtensions for Financial Services (XFS) layer, to send unauthorized commands to cash-dispensing hardware and force the machine to dispense money without a legitimate transaction, customer account access, or bank authorization. Early activity focused on NCR ATMs, while later variants expanded portability across additional vendors through support for standard middleware and multivendor platforms such as KAL Kalignite.
Ploutus is associated with direct cash extraction rather than payment fraud against customer accounts. Operators typically require physical access to the ATM to install the malware, commonly by opening the cabinet and modifying or replacing storage media, though some variants and reporting indicate remote-control features and broader operational flexibility. Historical variants introduced modularity, activation-code controls, and in some cases command mechanisms involving attached peripherals or mobile messaging, reflecting continued development and attempts to separate low-level installers from cash-out crews. Ploutus.D is notable for communicating through the KAL Kalignite framework, enabling adaptation across multiple ATM manufacturers with relatively limited code changes.
The malware has been repeatedly linked to organized criminal jackpotting operations in Latin America and later the United States, and it has been cited in law-enforcement reporting on large-scale ATM theft conspiracies. It has also been discussed in connection with underground resale and malware-as-a-service style activity within the ATM crime ecosystem. Financial institutions, ATM operators, and vendors are the primary victims, particularly where legacy Windows deployments, weak physical protections, outdated software, exposed service interfaces, or insufficient host integrity controls remain in place. Ploutus remains a significant example of cyber-physical financial malware that bridges endpoint compromise and direct manipulation of cash-dispensing hardware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A well-known strain of malware called Ploutus is among the types of malicious code being used in these hit.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
“Attackers frequently exploit generic service keys, outdated operating systems or unsecured USB ports before installing malware that bypasses bank authorisation controls,” he added.
“Attackers frequently exploit generic service keys, outdated operating systems or unsecured USB ports before installing malware that bypasses bank authorisation controls,” he added.
“Custom services… HKLM\SYSTEM\CurrentControlSet\Services\ … Services pointing to non-standard install paths… generic or deceptive names: ATM Service, Dispenser Service”
“Attackers frequently exploit generic service keys, outdated operating systems or unsecured USB ports before installing malware that bypasses bank authorisation controls,” he added.
“Custom services… HKLM\SYSTEM\CurrentControlSet\Services\ … Services pointing to non-standard install paths… generic or deceptive names: ATM Service, Dispenser Service”
“Services running with generic or deceptive names: ATM Service, Dispenser Service” and “Executable files not expected on the hard drive… NCRApp.exe… WinMonitor.exe…”
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
39 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ATM malware used for jackpotting attacks to trigger unauthorized cash dispensing from ATMs.
Listed as a notable commodity malware family that researchers used to analyze in depth.
A sophisticated ATM malware family used for jackpotting by sending unauthorized commands to ATM cash dispensing modules.
ATM jackpotting malware that manipulates cash dispensers to bypass authentication and transaction validation and directly command ATMs to dispense cash.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.