Crims hit a $20M jackpot via malware-stuffed ATMs
ID: 84921438-db95-58cc-ad5e-be0c804ea3fc
STIX ID: report--84921438-db95-58cc-ad5e-be0c804ea3fc
Feed Name: The Register (Security)
The FBI warns of a rise in ATM jackpotting, a malware-assisted cyber-physical attack (often using Ploutus) that exploits the XFS API to make ATMs dispense cash without authorization. Attackers gain physical access (generic keys), replace or infect ATM hard drives, and deploy malware; there have been ~1,900 incidents since 2020 (700+ in 2025) and over $20M stolen. The alert lists Windows-based executables, scripts, USB insertion event IDs, and other digital/physical IOCs and advises reporting suspicious activity to the FBI or IC3.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
