Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Java-based ATM malware from Latin America capable of cashing out ATMs; installation requires access to the bank network.
A targeted Java-based ATM malware that injects into the legitimate ATM control process, starts an HTTP server for remote command execution, can dispense cash, run shell commands via cmd.exe, load JAR files, enumerate and invoke Java classes/functions, and execute attacker-supplied JavaScript on the victim ATM.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.