Skimer is an ATM-focused malware family first publicly identified in 2009 and widely regarded as the first known malware specifically designed to target automated teller machines. It operates primarily as a virtual skimmer and backdoor for ATM systems, enabling attackers to steal payment-card track data, capture PIN-pad input and other transaction-related information, and in some variants trigger unauthorized cash dispensing. Skimer has been observed in multiple versions, including an earlier variant that combined data theft and cash-out functionality and a later reduced variant focused on data collection, as well as improved samples identified in 2016 that showed continued development.
Skimer targets Windows-based ATM environments and abuses ATM middleware and XFS-accessible functionality to interact with peripherals such as card readers, PIN pads, and cash dispensers. Later variants were reported to patch ATM service components and load a malicious library into the ATM software stack to gain full access to XFS functions. The malware has used operator authentication mechanisms such as authorization codes, master-card style activation, or specially crafted payment cards, after which an authenticated operator can issue commands through the PIN pad. Documented functions include dispensing cash from selected cassettes, collecting and printing stolen card data, logging PIN-related input, updating the malware, enabling debugging, and self-removal.
Historically, Skimer infections were manually installed and required physical access to the ATM, consistent with early ATM malware tradecraft that relied on local access through removable media or direct servicing interfaces. Campaigns involving Skimer were reported against ATMs in Eastern Europe, including Russia and Ukraine, and the malware is part of the broader criminal ATM-malware ecosystem that has disproportionately affected regions with older or less frequently updated ATM infrastructure. Skimer is notable both for pioneering ATM malware operations and for demonstrating the convergence of card-data theft and jackpotting capabilities within a single family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
After successful installation, the sample patches the XFS executable (SpiService.exe) entry point, in order to add a LoadLibrary call to the dropped netmgr.dll file.
A recent review of its functionality also indicates that it may also attempt to steal users' PINs by retrieving the encrypted pin pad encryption keys from the system.
C:\Windows\Temp\attrib4 logs data from different APIs responsible for the communication with the keyboard (effectively logging data such as the pin)
all of the known ATM malware attacks provide the attackers a way to install arbitrary programs on the cash machines in order to empty their cash cassettes (i.e., jackpotting the machine), log all customer card transactions (i.e., virtual skimming), or both.
Skimer functions as a virtual skimming device that attempts to steal bank card numbers and details of the account and owner details stored on the magnetic stripe tracks 1 and 2.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ATM malware/backdoor that infects ATM systems, patches the XFS service executable to load a malicious DLL, activates when a specially crafted magic card is inserted, authenticates operators with a session key, and supports cash dispensing, card data collection, PIN/API logging, self-deletion, debugging, and malware updates.
ATM malware that steals card data from magnetic stripe tracks, may retrieve PIN-related encryption material, and provides a backdoor menu for operators to trigger cash dispensing from ATM cash modules.
ATM malware targeting Diebold ATMs; used for jackpotting and virtual skimming. v2009 can read PIN pad input, dispense cash, and collect transaction data, while v2011 focuses on collecting transaction/card data and encrypting logs.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.