Researchers detailed ATMii (Backdoor.Win32.ATMii), an ATM malware family designed to make infected machines dispense cash on command. The malware was shared by a financial-sector partner and consists of two components: an injector executable and an injected DLL that targets the proprietary atmapp.exe process and hooks XFS functionality through msxfs.dll. Once running, ATMii can scan for the cash dispenser service, collect cassette information, dispense a specified amount in a chosen currency, and delete its command file after execution.
The malware requires direct access to the target ATM, either over the network or through physical access such as a USB device, underscoring the continued risk of local and internal compromise in ATM environments. Researchers described the code as relatively unsophisticated and noted signs such as a likely fake 2013 compilation timestamp and lack of support for Windows XP, despite that operating system remaining common in ATMs at the time. Recommended defenses included application whitelisting and device control to block unauthorized binaries and removable media used in cash-out attacks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Researchers first received samples of the ATMii ATM malware family from a financial-industry partner. The malware was designed to enable cash dispensing from infected ATMs.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.