ATMitch is ATM cash-dispensing malware used in financially motivated jackpotting attacks against banks. Publicly identified by Kaspersky in April 2017, it was investigated in connection with a June 2016 intrusion at a Russian bank. Attackers remotely installed and executed it through Remote Desktop Protocol access from within the bank's network, enabling unauthorized cash withdrawals from compromised ATMs.
ATMitch targets Windows-based ATMs and uses standard XFS middleware to control cash-dispenser functions, allowing operation across different XFS-compatible ATM models. It has no user interface or built-in authentication mechanism. Instead, it reads single-character instructions from an attacker-supplied local text file. Supported operations include initializing and unlocking XFS, opening the dispenser, retrieving or setting the dispenser identifier, dispensing cash, canceling operations, and exiting. After processing an instruction, it logs the result and deletes the instruction file. Attackers removed the malware after the observed cash-out operation; the recovered sample itself did not attempt to conceal its presence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an example of malware used to compromise bank and credit union ATMs for jackpotting. No family-specific capabilities or connection to the sanctioned individuals are established.
ATM malware used to remotely administer and cash out ATMs. It is installed via RDP access from within the bank network, reads single-character commands from command.txt, uses the standard XFS library to control ATM functions such as opening the dispenser and dispensing cash, logs command results, and deletes the command file after execution.
ATM malware that gains remote access control over ATMs at Russian banks.
Named ATM malware family included in the IOC set; no further functionality described in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.