Kaspersky Lab reported that the Tyupkin malware infected more than 50 ATMs, primarily Microsoft Windows 32-bit machines from a major manufacturer, and enabled criminals with physical access to authenticate to the terminal, inspect how much cash was loaded in each cassette, and force the machine to dispense 40 notes from a selected cassette. Investigators said the malware was installed using a bootable CD, persisted through a Windows Run registry key, and interacted with the dispenser through the standard ATM library MSXFS.dll.
The campaign was concentrated in Eastern Europe, but telemetry suggested the malware had also surfaced in the United States, India, and China. Kaspersky said Tyupkin operated only during specific nighttime windows and used per-session keys to restrict unauthorized use, while later variants added anti-debugging, anti-emulation, and the ability to disable McAfee Solidcore. The findings highlighted a shift from card skimming toward direct attacks on banks through ATM cash-out operations, prompting recommendations for stronger physical ATM security, non-default locks and keys, functioning alarms, and dedicated security software.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Kaspersky Lab published research identifying the malware family as Backdoor.MSIL.Tyupkin and describing its operation, including time-window restrictions, per-session keys, and later anti-debugging and anti-emulation features. The company warned that the campaign reflected a shift from card skimming toward direct attacks on financial institutions and recommended stronger ATM physical and software security.
The malware allowed criminals with physical access to an infected ATM to authenticate with a session key, inspect cash cassette balances, and command the machine to dispense 40 notes from a selected cassette. Kaspersky said the attackers installed the malware via a bootable CD and used the ATM library MSXFS.dll to control the cash dispenser.
Kaspersky investigated a campaign in which attackers compromised more than 50 ATMs, primarily Microsoft Windows 32-bit systems from a major ATM manufacturer, in Eastern Europe. Based on VirusTotal submissions, Kaspersky believed related samples had also appeared in the United States, India, and China.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.