top of page

ATM JACKPOTTING USING FILELESS MALWARE

  • Komodo Research
  • Mar 2, 2019
  • 4 min read

Updated: Jul 22, 2025


atm jackpotting using fileless malware

We see it in movies, read about it on security blogs, and, the more sinister among us, dream about doing it – but what does it really take to perform a jackpotting attack on a bank ATM?

As part of a contract with a large commercial bank, we were tasked with assessing the security of an ATM protected by a well-known security product meant to block unauthorized code execution on sensitive systems. We were given full network and physical access to an NCR ATM — a very common ATM extensively used worldwide — and asked to find possible attack vectors.

So… How does this ATM malarkey work?

This post describes the challenges we faced in the process of compromising the ATM. So, before we get to the fun part, which involves bypassing that security software and making the ATM spew cash notes, we first have to understand the software architecture of modern ATMs:


window based applications

A typical ATM is based on a Windows machine with many hardware components, such as a notes and coins dispenser, camera, touchscreen, card reader, and so on. Every ATM manufacturer creates their own drivers and service providers for these hardware components. In theory, a common middleware named XFS, which most ATM manufacturers adhere to, makes running the same application across hardware vendors possible. XFS deals purely with the aspect of delegating instructions to the hardware component and has no security mechanisms. If you can run compiled code on the ATM, its game over.  We used that middleware to instruct the cash dispenser to repeatedly dispense notes until it had none left.

Having no experience in developing with XFS middleware, we tried to find documentation and example code online. Sadly, we couldn’t find any beyond the CEN generic and often documentation was missing. Luckily, we were not the first ones to try this attack. There are several known ATM malwares capable of dispensing cash from NCR ATMs. While obviously no source code is available, there are many writeups about ATM malwares that does wonders in filling the gaps about the NCR XFS implementation . We even went as far as looking at the “GreenDispencer” malware, just to catch some arguments passed to XFS APIs:


atm jackpotting

Eventually, we came up with the following routine:
Import msxfs.dll Call WFSStartUp Call WFSOpen with the name of the cash dispenser device (obtained from the ATM registry) Call WFSExecute with the WFS_CMD_CDM_DISPENSE command and WFSCDMDISPENSE structure with the desired amount to be dispensed set Call WFSExecute with the WFS_CMD_CDM_PRESENT command to present the cash notes Loop until cash cassettes are empty
Bypassing weak security

Now that we had a sense of what complied code we wanted to execute on the ATM, we were left with bypassing the endpoint hardening software, which seemed challenging at first — all executables on the system were put on whitelist and any attempt to execute something out of place was blocked. Luckily though, the bank was kind enough to whitelist the PowerShell executable, as the ATM startup routine uses some ps1 scripts. That essentially means we could run compiled DLL by using PowerShell to reflectively load it, similar to the method used by Invoke-MimiKatz. This method has the added benefit of being relatively stealthy as it does not write our malware to disk – its “file-less”.

This fileless technique exemplifies how sophisticated ATM attacks have become. With the rise in black-market demand for ATM malware source code, organizations must prioritize proactive defenses like regular code audits and robust endpoint protections. It also emphasizes the importance of thorough ATM penetration testing to uncover such stealthy attack vectors before bad actors do.

To put everything together, our malware would be a PowerShell script that loads an embedded base64 encoded DLL, which in turn uses the XFS middleware to dispense cash notes. Obviously, we skipped some of the implementation details, and will not be providing sample code as the bank was understandably sensitive about it. However, filling the gaps should be straight forward from here.

Money time

Now that we had our malware, we came up with 2 attack vectors:

Attackers with access to the bank ATM network could remotely access the ATM and execute the malwareAttackers with physical access to the ATM could plug a “rubber ducky”  loaded with the script and have it executed within minutes.

The first one was straight forward. With enough access any ATM can be targeted remotely from the bank’s internal network. How hard it will be to get that access level depends on the security architecture of the bank’s network, which is beyond the scope of this blog. We were given a remote desktop connection to a lab ATM and successfully executed the malware, dispensing (fake) notes to the surprise of the technicians manning the lab.

The second vector presented more challenges. Surprisingly, we discovered that ATMs run with a local administrator logged in. All we had to do was plug in a keyboard. Granted, getting to an exposed USB port on an ATM is everything but trivial (yet not impossible ). Additionally, attacks by insiders are not unheard of. After plugging the keyboard, we quickly found a key sequence which escapes the kiosk mode and provides us with a fully functioning windows machine:



Invoke-Jackpot

Using that sequence, we built a rubber ducky script containing our PowerShell script. Since the rubber ducky is typing the script character by character, and the script ended up just shy of 100KB after being compressed and base64 encoded, the loading time of the rubber ducky was about 10 minutes. It can be reduced by further minimizing the PowerShell script and dynamically linking the embedded DLL.


Komodosec uniform

Standard-issue Komodosec uniform

Mitigation

After the security assessment, the bank justifiably dropped the security software in favor of another solution, which among other security mechanisms puts PowerShell into Constrained Language Mode. This limits the capability of scripts to use WIN32 APIs, hindering attempts to reflectively load compiled executables – making our malware obsolete.

Yoni Zach, information security specialist 

 
 
 

6 Comments


rattittbi.nit.aac
11 hours ago

b52club14.com dạo này thấy mọi người nhắc hoài nên mình cũng bấm vào coi thử cho biết chứ không có ngồi chơi hay đọc kỹ gì đâu. Vừa vào cái mình để ý ngay là giao diện nhìn khá thoáng, không bị rối mắt kiểu nhét quá nhiều chữ một chỗ. Mấy phần thông tin họ chia theo từng khối rõ ràng nên lướt nhanh vẫn hiểu đang ở mục nào, đỡ phải kéo lên kéo xuống tìm. Mình cũng thích cái cách họ gom menu lại gọn gàng, nằm chỗ dễ thấy nên chuyển trang khá tiện, bấm vài cái là quen tay luôn. Nói chung cảm giác dùng thử vài phút thấy nhẹ nhàng, không bị “ngợp” như…

Like

christinejones.5999.9
17 hours ago

tải sun win là cái cụm mình thấy lướt đâu cũng gặp nên hôm bữa rảnh mới bấm vào coi thử trang trông ra sao. Mình không có đọc kỹ nội dung hay gì, chủ yếu xem giao diện có dễ chịu không thôi. Cảm giác đầu tiên là trang làm khá thoáng, chia nội dung theo từng khối rõ ràng nên kéo xuống là bắt nhịp được ngay, không bị chữ dồn dập nhìn mệt mắt. Mình cũng để ý phần menu đặt khá dễ thấy, bấm qua lại mấy mục nhanh, không kiểu giấu sâu phải tìm hoài. Nói chung lướt vài phút là hiểu họ sắp xếp thông tin theo nhóm thế nào, nhất là cách họ…

Like

bentieshamarsh.al.2l11.1
4 days ago

Mình thường lướt tin về bitcoin rồi xem thêm vài góc nhìn phân tích kỹ thuật để bắt nhịp thị trường crypto mỗi ngày. Đọc kèm mấy bài dự đoán giá bitcoin và tin tức về altcoin, memecoin giúp mình hình dung tổng quan rõ hơn trước khi quyết định vào lệnh hay chờ thêm. Có lúc mình cũng vào xem chia sẻ từ cộng đồng, nhiều người nhắc nên tham khảo thêm phân tích on-chain và các tin vắn được chọn lọc vì hay bám sát dữ liệu thực tế. https://tapchibitcoin.io/ là chỗ mình hay ghé để cập nhật nhanh, sau đó tự đối chiếu lại với biểu đồ cho chắc. Với các coin lớn như ETH, XRP hay…

Like

maisidel.gado1.9.4
4 days ago

Mình chơi xổ số kiểu giải trí là chính, chủ yếu mở kết quả lên xem cho vui chứ không đặt nặng chuyện đổi đời. Trước đây nghe bạn bè rỉ tai đủ loại “cầu” với mẹo này nọ, mình cũng thử quan sát một thời gian cho biết. Theo dõi lâu hơn thì thấy đôi lúc có vài chi tiết lặp lại khiến mình chú ý, nhưng mình vẫn nhắc bản thân đừng quá tin. Mỗi lần đọc mấy bài nhận định, mình hay ghi ra vài ý ngắn gọn rồi chờ kết quả để đối chiếu, coi có phải mình đang tự gán ghép không. Trúng chút thì vui, còn sai thì coi như trải nghiệm. Dạo gần…

Like

giecphangqua.n.h.g.h.u.n.g
6 days ago

Sc88 mình thấy bạn bè nhắc hoài nên tiện tay ghé thử xem trang chủ ra sao. Không kiểu ngồi đọc kỹ đâu, mình chỉ lướt nhanh để coi bố cục và cách họ sắp xếp thông tin. Cảm giác đầu tiên là giao diện nhìn sáng, chia khối rõ ràng nên kéo xuống không bị rối mắt. Có một đoạn giới thiệu tổng quan về thương hiệu đặt khá dễ thấy, đọc lướt vài dòng là nắm được họ đang nói về hệ sinh thái với công nghệ hiện đại và hướng phát triển ổn định. Mình cũng thích kiểu tiêu đề nổi bật, nhìn cái là biết phần nào đang nói về gì, không phải đoán. Nói chung…

Like
bottom of page