Ploutus Malware Drains U.S. ATMs Without a Card or Account — FBI Issues Emergency FLASH Alert
On Tue, Feb 19, 2026, the FBI issued a FLASH alert (FLASH-20260219-001) to banks and ATM operators regarding an increase in malware-enabled “jackpotting.” This technique allows criminals to exploit physical access and software vulnerabilities to dispense…
On Tue, Feb 19, 2026, the FBI issued a FLASH alert (FLASH-20260219-001) to banks and ATM operators regarding an increase in malware-enabled “jackpotting.” This technique allows criminals to exploit physical access and software vulnerabilities to dispense cash from ATMs without conducting legitimate transactions. This trend has been observed across the United States.
The alert highlights the Ploutus malware family, which targets ATMs by exploiting eXtensions for Financial Services (XFS), a software layer that controls dispenser hardware. Unlike typical withdrawal processes, where the ATM application sends XFS commands for bank approval, Ploutus enables unauthorized command execution, bypassing the need for bank authorization.
The FBI analysts have compiled indicators of compromise and other technical details to assist organizations in responding to such incidents. It is reported that over 700 out of approximately 1,900 jackpotting incidents since 2020 occurred in 2025, resulting in losses exceeding $20 million.
Infection Mechanism and On-Box Control
Once physical access to an ATM is gained, attackers may remove the hard drive, connect it to another computer to copy the malware, reinstall it, and reboot the machine. Alternatively, they may replace it with a foreign drive or external device pre-loaded with the malware, sometimes using a USB hub or keyboard.
The FBI analysts have compiled indicators of compromise and other technical details to assist organizations in responding to such incidents.
Since many ATMs operate on Windows, this approach can be adapted across different manufacturers with minimal code adjustments. The malicious program interacts directly with hardware through XFS, functioning even when the ATM is offline, without triggering network alerts.
Indicators of compromise include unexpected executables such as Newage.exe, NCRApp.exe, WinMonitor.exe, or sdelete.exe, new folders under paths like C:\Users\SSAuto1\AppData\Local\P, unauthorized remote tools like AnyDesk or TeamViewer, and registry autoruns or custom services with generic names such as “ATM Service” and “Dispenser Service.”
The FBI recommends the following preventive measures:
Change standard locks and add tamper sensors and camera coverage. Enable disk encryption and hardware device whitelisting. Validate each ATM against a trusted gold image and baseline hashes. Enable targeted Windows auditing for USB insertion, file writes, process creation, and log clearing (Event IDs 6416, 4663, 4688, 1102).
Organizations are encouraged to report suspected jackpotting to a local FBI field office or the Internet Crime Complaint Center (IC3).
Based on reporting by Cyber Security News.
