Researchers identified ATMJaDi, a targeted Java-based ATM malware used to cash out machines in Latin America after samples were uploaded from Mexico and later Colombia. Unlike most ATM malware, it does not rely on standard ATM middleware such as XFS, JXFS, or CSC; instead, it abuses proprietary Java classes embedded in a victim bank’s ATM software, making it effective only in a narrow set of environments. The malware was observed packaged as INJX_PURE.jar and was designed to interact directly with the ATM control process.
Once installed, ATMJaDi injects into the ATM application and starts an HTTP server that can trigger cash dispensing, execute JavaScript, load additional JAR files, enumerate JVM classes, and run Windows shell commands through cmd.exe. Researchers said the malware requires prior installation and network access to the targeted ATM, indicating the operators likely first compromised the bank’s internal infrastructure to reach ATM-connected networks. The code’s multilingual terminal messages included awkward Russian phrasing assessed as a likely false flag, while the malware’s use of custom bank-specific classes suggested the attackers had detailed knowledge of the victim ATM environment and possibly access to source code or a similarly configured test system.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
In spring 2019, researchers discovered a new Java-based ATM malware later named ATMJaDi. The samples were uploaded to a multiscanner service from Mexico and later from Colombia, indicating activity in at least those locations.
Securelist published an analysis describing ATMJaDi as a highly targeted ATM cash-out malware that abuses proprietary Java classes from a victim bank’s ATM software instead of standard ATM libraries. The report also assessed that the operators likely had prior access to the bank’s infrastructure or ATM environment to deploy and control the malware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.