Kaspersky reported that ATM and point-of-sale malware activity rose sharply in 2018 and remained high in 2019, with detections concentrated in Russia, Brazil, Iran, Vietnam, India, the United States, and several European countries. Russia consistently recorded the highest number of affected devices, underscoring the global scale of attacks targeting payment infrastructure.
The report linked the sustained threat to outdated software, unpatched vulnerabilities, weak physical security, and the operational limits of vendor-managed ATM environments. It identified active malware families including ATMJackpot, WinPot, Ice5, ATMTest, Peralta, ATMWizX, ATMDtrack, ATMgot, ATMqotX, and ATMJaDi, which support cash-out schemes, card-data theft, and anti-forensic functions, while noting that older malware continues to be reused and that a malware-as-a-service trend is emerging from Latin America.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
The number of unique devices encountering ATM/PoS malware remained high and increased slightly again in 2019. Russia recorded 2,306 affected devices, with Iran second at 1,178, followed by Brazil, Vietnam, and India.
ATMgot and ATMJaDi were highlighted as part of elevated ATM/PoS malware activity in spring 2019. ATMgot supported anti-forensic deletion of infection traces and video files, while ATMJaDi was a Java-based cash-out malware requiring access to the bank's network.
ATMDtrack appeared in late 2018 and reportedly first affected victims in India. The malware collected enough payment card data from infected ATMs to enable card cloning and also dropped the Dtrack spyware tool.
The number of unique devices protected by Kaspersky that encountered ATM/PoS malware grew by double digits in 2018. Russia again recorded the highest number of affected devices with 1,370, while Brazil, Italy, the United States, Vietnam, and India also saw substantial activity.
ATMTest was identified in 2018 as a multi-stage ATM malware requiring console access. Its operation implied prior compromise of a bank's network.
WinPot was discovered in Eastern Europe in early 2018. The malware was designed to make infected ATMs dispense cash automatically from the most valuable cassettes.
In 2017, Russia recorded the highest number of unique devices affected by ATM/PoS malware at 1,016, followed by Brazil with 423. Other countries specifically noted for 2017 included Vietnam, the United States, and India.
The ATMJackpot malware first appeared in Taiwan in 2016. It infects banks' internal networks to enable direct ATM cash withdrawals.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.