Investigators tied a targeted ATM cash-out intrusion at a Russian bank to ATMitch, a malware family designed to remotely administer ATMs from inside a bank network. In the incident, attackers gained access to the bank environment, reached ATMs over RDP, and deployed the malware as tv.dll, later removing it to hinder recovery. Although the original executables were not preserved, forensic analysis of ATM hard drives recovered log files and deleted filenames that allowed researchers to identify the tool and reconstruct its operation.
ATMitch uses the XFS library to send dispenser instructions to cash machines through a one-character instruction file named command.txt, giving operators a simple way to trigger cash withdrawals on compatible devices. The case aligns with broader reporting on ATM cash-out malware, including material associated with Operation Fast Cash and Hidden Cobra, underscoring how attackers have used specialized malware to manipulate ATM infrastructure and dispense cash directly from compromised banking environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A GitHub repository added a PDF titled "Operation Fast Cash - Hidden Cobra’s AIX PowerPC malware dissected," making the analysis document available in the repository. The visible repository metadata shows the PDF was uploaded on December 31, 2018.
In June 2016, criminals gained control of ATMs at a Russian bank, uploaded malware to them, and remotely administered the machines to steal cash. The attackers removed the malware after the cash-out operation, complicating recovery of the original executables.
After the attack, the bank’s forensic team recovered log artefacts and deleted filenames from an ATM hard drive, then used the recovered information to create a YARA rule and identify a malware sample uploaded as "tv.dll." The sample, dubbed ATMitch, was linked to remote ATM administration via XFS commands over RDP access from within the bank network.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.