Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

FBI Issues Emergency Alert as Ploutus Malware Drains U.S. ATMs Without Cards or Accounts

Ploutus malware is facilitating a series of "jackpotting" attacks that deplete U.S. ATMs without the need for a bank card, customer account, or bank authorization. In response, the FBI has issued an emergency FLASH alert to financial institutions across…

Ploutus malware is facilitating a series of "jackpotting" attacks that deplete U.S. ATMs without the need for a bank card, customer account, or bank authorization. In response, the FBI has issued an emergency FLASH alert to financial institutions across the nation.

The FBI alert indicates that threat actors are utilizing Ploutus and related ATM jackpotting malware to gain control over cash machines throughout the United States, bypassing standard banking transactions. Ploutus exploits the eXtensions for Financial Services (XFS) software layer, which manages ATM hardware operations like cash movement, card acceptance, and receipt printing. This malware issues its own commands directly to the dispenser, releasing cash on demand without involving the bank's authorization systems.

Once installed, Ploutus effectively transforms the ATM into an independent cash machine under criminal control, allowing rapid cash-out operations. These operations are often completed in mere minutes and frequently detected only after significant sums have already been stolen.

The FBI notes that Ploutus-based tools can be adjusted to function across various ATM manufacturers with minimal code alterations, as they target the underlying Windows systems used by many machines.

To deploy Ploutus, attackers first gain physical access to the ATM, often by using generic keys that match standard manufacturer locks. The FBI FLASH also highlights the usage of unauthorized remote-access tools such as AnyDesk or TeamViewer, as well as USB keyboards, hubs, and flash drives directly connected to the ATM for malware interaction or staging.

Ploutus malware is facilitating a series of "jackpotting" attacks that deplete U.S.
Madison Drake · Thehackingpost

In some cases, criminals remove the ATM’s hard drive, connect it to another computer to copy the malware, then reinstall the drive and reboot the ATM, activating the malicious code. Alternatively, they may replace the original hard drive with a foreign drive or external device preloaded with Ploutus and supporting tools.

Once operational, Ploutus communicates directly with the dispenser hardware, bypassing the ATM’s original software security controls and allowing the execution of multiple unauthorized withdrawals.

Digital indicators observed on compromised ATMs include unexpected executables such as Newage.exe, Color.exe, Levantaito.exe, NCRApp.exe, Promo.exe, WinMonitor.exe, WinMonitorCheck.exe, and Anydesk1.exe, along with associated batch files and logs like C.dat and Restaurar.bat. The FBI also provides MD5 hashes linked to known Ploutus samples and advises banks to compare installed files against a cryptographically verified "gold image" baseline of approved software and configurations.

Since 2020, the FBI has tracked approximately 1,900 ATM jackpotting incidents in the U.S., with over 700 attacks and more than 20 million USD in losses occurring in 2025 alone. The increase in cases and Ploutus' ability to drain ATMs without customer interaction prompted the Bureau to circulate the FLASH advisory to financial institutions, ATM vendors, and security teams.

Advertisement

The alert urges organizations to strengthen both physical and logical defenses around ATMs, including replacing default locks, adding additional keyed barriers, deploying vibration and temperature sensors, and ensuring camera coverage of machines and vestibules. On the software side, the FBI recommends strong logging and audit policies for removable media, process creation, and system integrity events, as well as device and software whitelisting to block unauthorized USB devices and executables.

Banks are encouraged to enable hard drive encryption, verify firmware with digital signatures, and configure automatic shutdown or "out of service" states when a combination of jackpotting indicators is detected. The FBI requests that victims and operators promptly report suspicious activity, including ATM models, logs, observed files, and network details, to local FBI field offices or the Internet Crime Complaint Center (IC3) to assist in tracking and disrupting Ploutus-driven attacks.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories