Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
all of the known ATM malware attacks provide the attackers a way to install arbitrary programs on the cash machines in order to empty their cash cassettes (i.e., jackpotting the machine), log all customer card transactions (i.e., virtual skimming), or both.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an example of malware deployed on financial institutions' ATMs for jackpotting. The content does not establish SUCEFUL-specific behavior or use by Tren de Aragua.
Named ATM malware family included in the IOC set; no further functionality described in the content.
Named as a previously disclosed ATM malware family.
Prototype/test tool used to develop and validate ATM attack capabilities such as reading card data, PIN pad input, and controlling sensors. The report explicitly says it was not observed as part of a real-world attack.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.