Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Ripper shares features with previous ATM malware types (including Padpin and GreenDispenser) in that it can disable the machine’s network interface, therefore preventing real-time anti-fraud detection on the bank’s side, as well as delete attack-related data from the ATM to defeat post-infection forensics.
GreenDispenser also has the ability to delete itself... To prevent this forensics analysis GreenDispenser performs a deep delete using sdelete to remove itself from the ATM. The sdelete executable is imbedded within GreenDispenser, which is written to disk as “del.exe”.
If the checks pass, GreenDispenser proceeds to create a mutex called “dispenserprgm” to ensure that only a single instance of GreenDispenser is running.
The malware strains Proofpoint inspected were coded to run only if the year was 2015 and the month was earlier than September... Once run, GreenDispenser performs a check to verify that the current year is 2015 and the current month is earlier than September. If these conditions are not met, then GreenDispenser simply quits.
It achieves this by querying for peripheral names from the registry hive before defaulting to hardcoded peripheral names... attempts to query the registry location “HKEY_USERS\.DEFAULT\XFS\LOGICAL_SERVICES\class=PIN”... If the dispense cash option is selected, GreenDispenser attempts to query the registry location “HKEY_USERS\.DEFAULT\XFS\LOGICAL_SERVICES\class=CDM”.
The malware strains Proofpoint inspected were coded to run only if the year was 2015 and the month was earlier than September... Once run, GreenDispenser performs a check to verify that the current year is 2015 and the current month is earlier than September. If these conditions are not met, then GreenDispenser simply quits.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as an example of ATM jackpotting malware used to enable cash theft. The article does not provide GreenDispenser-specific technical details or attribute its use to Tren de Aragua.
ATM malware family cited as using the CEN/XFS framework to operate across hardware platforms and dispense cash.
ATM malware that interacts with XFS middleware to control the pinpad and cash dispenser, display a fake out-of-service screen, require a static PIN plus a dynamically derived second PIN via QR code, dispense cash from the ATM, and securely delete itself afterward to hinder forensics.
Multivendor ATM malware designed for jackpotting via XFS. It displays an out-of-service screen, uses a two-stage authentication process including a QR-code-based second key, tracks remaining bills, and includes a self-removal routine to erase traces.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.