WinPot, also known as ATMPot, is an ATM jackpotting malware family designed to force infected automated teller machines to dispense cash directly from their cassettes, particularly higher-value ones. It was first observed in early 2018 in Eastern Europe and is associated with attacks against ATMs from a major vendor. WinPot is part of the broader class of cash-out malware that abuses ATM middleware and local device access to trigger unauthorized dispensing without legitimate banking authorization.
The malware presents an operator-facing graphical interface styled like a slot machine. Its controls allow the attacker to scan the ATM for available cassettes, view cassette metadata such as denomination and note count, initiate dispensing from selected cassettes, and stop dispensing in progress. Multiple observed samples show only incremental evolution, with changes focused on packing, interface refinements, operating constraints, and evasion rather than major functional redesign.
A notable behavioral feature is time-gated execution. Some variants are configured to operate only within preset periods and will silently refuse to launch their interface outside the allowed window. This likely serves operational control and defense evasion purposes. Reported variants also used different packers over time, consistent with efforts to bypass security controls and maintain usability across targeted ATM environments.
WinPot has been linked to criminal ATM cash-out activity and was identified alongside other jackpotting malware such as Cutlet Maker. It has also been advertised in underground markets, indicating commoditization and availability to multiple operators. The malware’s deployment model is consistent with ATM intrusions that rely on local access to the ATM PC, including removable-media-based installation, and defensive guidance has emphasized device control and process allowlisting to block unauthorized execution.
WinPot targets Windows-based ATM environments and is relevant primarily to banks, ATM operators, cash management providers, and financial institutions running older or weakly hardened ATM systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ATM jackpotting malware designed to force ATMs to automatically dispense cash from selected cassettes, with a graphical interface that lets operators scan cassettes, start dispensing, and stop operations.
ATM malware that forces infected ATMs to dispense cash automatically, with time-dependent execution controls.
Named ATM malware family included in the IOC set; no further functionality described in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.