Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Ploutus Malware Drains U.S. ATMs Without a Card or Account — FBI Issues Emergency FLASH Alert

On Tue, Feb 19, 2026, the FBI issued a FLASH alert (FLASH-20260219-001) to banks and ATM operators regarding an increase in malware-enabled “jackpotting.” This technique allows criminals to exploit physical access and software vulnerabilities to dispense…

On Tue, Feb 19, 2026, the FBI issued a FLASH alert (FLASH-20260219-001) to banks and ATM operators regarding an increase in malware-enabled “jackpotting.” This technique allows criminals to exploit physical access and software vulnerabilities to dispense cash from ATMs without conducting legitimate transactions. This trend has been observed across the United States.

The alert highlights the Ploutus malware family, which targets ATMs by exploiting eXtensions for Financial Services (XFS), a software layer that controls dispenser hardware. Unlike typical withdrawal processes, where the ATM application sends XFS commands for bank approval, Ploutus enables unauthorized command execution, bypassing the need for bank authorization.

The FBI analysts have compiled indicators of compromise and other technical details to assist organizations in responding to such incidents. It is reported that over 700 out of approximately 1,900 jackpotting incidents since 2020 occurred in 2025, resulting in losses exceeding $20 million.

Infection Mechanism and On-Box Control

Once physical access to an ATM is gained, attackers may remove the hard drive, connect it to another computer to copy the malware, reinstall it, and reboot the machine. Alternatively, they may replace it with a foreign drive or external device pre-loaded with the malware, sometimes using a USB hub or keyboard.

The FBI analysts have compiled indicators of compromise and other technical details to assist organizations in responding to such incidents.
Laura Mitchell · Thehackingpost

Since many ATMs operate on Windows, this approach can be adapted across different manufacturers with minimal code adjustments. The malicious program interacts directly with hardware through XFS, functioning even when the ATM is offline, without triggering network alerts.

Indicators of compromise include unexpected executables such as Newage.exe, NCRApp.exe, WinMonitor.exe, or sdelete.exe, new folders under paths like C:\Users\SSAuto1\AppData\Local\P, unauthorized remote tools like AnyDesk or TeamViewer, and registry autoruns or custom services with generic names such as “ATM Service” and “Dispenser Service.”

The FBI recommends the following preventive measures:

Advertisement

Change standard locks and add tamper sensors and camera coverage. Enable disk encryption and hardware device whitelisting. Validate each ATM against a trusted gold image and baseline hashes. Enable targeted Windows auditing for USB insertion, file writes, process creation, and log clearing (Event IDs 6416, 4663, 4688, 1102).

Organizations are encouraged to report suspected jackpotting to a local FBI field office or the Internet Crime Complaint Center (IC3).

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories