Alice is a lightweight ATM cash-dispensing malware family discovered by Trend Micro in November 2016. It targets Windows-based ATMs using Microsoft XFS middleware, allowing operators to command cash dispensers without a legitimate withdrawal transaction. Its functionality focuses on emptying ATM cash cassettes rather than collecting customer card data. Deployment requires physical access to the ATM, but the malware can run without a dedicated installation procedure. Operators interact with a PIN-protected interface using an attached keyboard. Its use of XFS enables operation across compatible ATM hardware rather than restricting it to one manufacturer. Alice targets financial institutions through ATM jackpotting. The name is also used by a separate ransomware-as-a-service offering marketed as Alice in the Land of Malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK® Techniques ... Execution ... T1047 ... Windows Management Instrumentation
MITRE ATT&CK® Techniques ... Persistence ... T1053 ... Scheduled Task/Job
This ransomware uses the AES encryption algorithm to encrypt files ... After that, the malware starts the encryption process by enumerating the directories and encrypts the victim’s files using the AES-256-CTR algorithm, appending the extension as '.octo' ... Successful execution of Alice ransomware encrypts the victim’s files and appends the extension as '.alice' ... MITRE ATT&CK® Techniques ... T1486 ... Data Encrypted for Impact
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed among malware examples used in ATM jackpotting attacks against financial institutions. No Alice-specific behavior or campaign attribution is supplied.
RaaS ransomware advertised on cybercrime forums with a builder that generates Encryptor.exe and Decryptor.exe, appends the .alice extension to encrypted files, and drops ransom notes named 'How to Restore Your Files.txt'.
ATM cash-dispensing malware requiring physical installation and operator PIN entry to access the dispenser module and retrieve cash.
A lightweight, feature-lean ATM jackpotting malware focused solely on dispensing cash. It relies on XFS, does not need installation, requires a keyboard for commands, and appears designed to run on ATMs from any manufacturer using XFS.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.