Ploutus is a financially motivated ATM malware family first discovered in Mexico in 2013. It targets Windows-based ATMs and enables jackpotting by issuing unauthorized commands to cash-dispensing modules, bypassing normal bank authorization and transaction validation without debiting customer accounts. Initially associated with NCR machines, later variants expanded support to multiple ATM vendors. Ploutus abuses ATM middleware, including the eXtensions for Financial Services (XFS) layer; Ploutus.D uses the KAL Kalignite framework for multivendor compatibility.
Deployment typically requires physical access to ATM internals. Attackers install the malware by connecting external equipment to an ATM hard drive or replacing the drive with one already containing the malware. Operators then activate the malware and direct cash dispensing. Early versions supported commands through an externally attached keyboard, while Ploutus.B could receive SMS cash-out commands through a mobile phone installed inside the ATM. Variants use activation codes to restrict operator access, and later versions introduced remote-management functionality.
Some variants incorporate software protections that hinder debugging, reverse engineering, and forensic analysis, along with deletion functionality intended to conceal the compromise. Ploutus has been used in organized criminal operations against banks and credit unions in Latin America and the United States. U.S. authorities have linked Ploutus-enabled ATM-jackpotting conspiracies to Tren de Aragua.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The members of the network conspired to develop and deploy a variant of malware known as Ploutus, which was deployed on ATMs and used to permit the unauthorized withdrawal of currency.
Aguirre has allegedly developed the Ploutus malware used in ATM hacks and has been on the FBI's list of Ten Most Wanted Fugitives since March.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
“Attackers frequently exploit generic service keys, outdated operating systems or unsecured USB ports before installing malware that bypasses bank authorisation controls,” he added.
“Attackers frequently exploit generic service keys, outdated operating systems or unsecured USB ports before installing malware that bypasses bank authorisation controls,” he added.
“Custom services… HKLM\SYSTEM\CurrentControlSet\Services\ … Services pointing to non-standard install paths… generic or deceptive names: ATM Service, Dispenser Service”
“Attackers frequently exploit generic service keys, outdated operating systems or unsecured USB ports before installing malware that bypasses bank authorisation controls,” he added.
“Custom services… HKLM\SYSTEM\CurrentControlSet\Services\ … Services pointing to non-standard install paths… generic or deceptive names: ATM Service, Dispenser Service”
“Services running with generic or deceptive names: ATM Service, Dispenser Service” and “Executable files not expected on the hard drive… NCRApp.exe… WinMonitor.exe…”
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
49 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ATM-jackpotting malware used across Latin America and the United States since 2013. Attackers physically open an ATM, connect a personal device, and install the malware to force the machine to dispense cash. The reported operation also involved remote malware installation after accomplices accessed the machines. U.S. authorities allege links to Tren de Aragua and identify Anibal Alexander Canelon Aguirre as a key architect, but cybersecurity experts have not verified that he developed Ploutus. Authorities tracked at least 1,500 ATM-jackpotting attacks causing $40.7 million in losses; the article does not establish that every attack used Ploutus.
Malware deployed on ATMs to force cash dispensing without debiting customer accounts. It includes anti-analysis capabilities and can erase itself from infected systems to conceal its tracks. The article reports the arrest of Anibal Alexander Canelon Aguirre, its alleged developer and a suspected leader of Tren de Aragua’s ATM jackpotting activities.
Malware used to make compromised ATMs dispense cash in jackpotting attacks. It incorporates software protection utilities to hinder reverse engineering and debugging, along with files that delete the malware to conceal its deployment. The alleged conspiracy stole more than $5.4 million through attacks against banks and credit unions during the stated period.
Forces ATMs to dispense cash without debiting an account. The content describes anti-analysis protections that hinder reverse engineering and debugging, alongside components that delete the malware to conceal its deployment. Authorities allege that Anibal Alexander Canelon Aguirre developed Ploutus for an ATM jackpotting conspiracy linked to Tren de Aragua. The conspiracy targeted or conducted attacks in 47 U.S. states, the District of Columbia, and several foreign nations. These allegations remain subject to trial.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.