ATM JACKPOTTING USING FILELESS MALWARE
- Komodo Research
- Mar 2, 2019
- 4 min read
Updated: Jul 22, 2025

We see it in movies, read about it on security blogs, and, the more sinister among us, dream about doing it – but what does it really take to perform a jackpotting attack on a bank ATM?
As part of a contract with a large commercial bank, we were tasked with assessing the security of an ATM protected by a well-known security product meant to block unauthorized code execution on sensitive systems. We were given full network and physical access to an NCR ATM — a very common ATM extensively used worldwide — and asked to find possible attack vectors.
So… How does this ATM malarkey work?
This post describes the challenges we faced in the process of compromising the ATM. So, before we get to the fun part, which involves bypassing that security software and making the ATM spew cash notes, we first have to understand the software architecture of modern ATMs:

A typical ATM is based on a Windows machine with many hardware components, such as a notes and coins dispenser, camera, touchscreen, card reader, and so on. Every ATM manufacturer creates their own drivers and service providers for these hardware components. In theory, a common middleware named XFS, which most ATM manufacturers adhere to, makes running the same application across hardware vendors possible. XFS deals purely with the aspect of delegating instructions to the hardware component and has no security mechanisms. If you can run compiled code on the ATM, its game over. We used that middleware to instruct the cash dispenser to repeatedly dispense notes until it had none left.
Having no experience in developing with XFS middleware, we tried to find documentation and example code online. Sadly, we couldn’t find any beyond the CEN generic and often documentation was missing. Luckily, we were not the first ones to try this attack. There are several known ATM malwares capable of dispensing cash from NCR ATMs. While obviously no source code is available, there are many writeups about ATM malwares that does wonders in filling the gaps about the NCR XFS implementation . We even went as far as looking at the “GreenDispencer” malware, just to catch some arguments passed to XFS APIs:

Eventually, we came up with the following routine:
Import msxfs.dll Call WFSStartUp Call WFSOpen with the name of the cash dispenser device (obtained from the ATM registry) Call WFSExecute with the WFS_CMD_CDM_DISPENSE command and WFSCDMDISPENSE structure with the desired amount to be dispensed set Call WFSExecute with the WFS_CMD_CDM_PRESENT command to present the cash notes Loop until cash cassettes are empty
Bypassing weak security
Now that we had a sense of what complied code we wanted to execute on the ATM, we were left with bypassing the endpoint hardening software, which seemed challenging at first — all executables on the system were put on whitelist and any attempt to execute something out of place was blocked. Luckily though, the bank was kind enough to whitelist the PowerShell executable, as the ATM startup routine uses some ps1 scripts. That essentially means we could run compiled DLL by using PowerShell to reflectively load it, similar to the method used by Invoke-MimiKatz. This method has the added benefit of being relatively stealthy as it does not write our malware to disk – its “file-less”.
This fileless technique exemplifies how sophisticated ATM attacks have become. With the rise in black-market demand for ATM malware source code, organizations must prioritize proactive defenses like regular code audits and robust endpoint protections. It also emphasizes the importance of thorough ATM penetration testing to uncover such stealthy attack vectors before bad actors do.
To put everything together, our malware would be a PowerShell script that loads an embedded base64 encoded DLL, which in turn uses the XFS middleware to dispense cash notes. Obviously, we skipped some of the implementation details, and will not be providing sample code as the bank was understandably sensitive about it. However, filling the gaps should be straight forward from here.
Money time
Now that we had our malware, we came up with 2 attack vectors:
Attackers with access to the bank ATM network could remotely access the ATM and execute the malwareAttackers with physical access to the ATM could plug a “rubber ducky” loaded with the script and have it executed within minutes.
The first one was straight forward. With enough access any ATM can be targeted remotely from the bank’s internal network. How hard it will be to get that access level depends on the security architecture of the bank’s network, which is beyond the scope of this blog. We were given a remote desktop connection to a lab ATM and successfully executed the malware, dispensing (fake) notes to the surprise of the technicians manning the lab.
The second vector presented more challenges. Surprisingly, we discovered that ATMs run with a local administrator logged in. All we had to do was plug in a keyboard. Granted, getting to an exposed USB port on an ATM is everything but trivial (yet not impossible ). Additionally, attacks by insiders are not unheard of. After plugging the keyboard, we quickly found a key sequence which escapes the kiosk mode and provides us with a fully functioning windows machine:

Invoke-Jackpot
Using that sequence, we built a rubber ducky script containing our PowerShell script. Since the rubber ducky is typing the script character by character, and the script ended up just shy of 100KB after being compressed and base64 encoded, the loading time of the rubber ducky was about 10 minutes. It can be reduced by further minimizing the PowerShell script and dynamically linking the embedded DLL.

Standard-issue Komodosec uniform
Mitigation
After the security assessment, the bank justifiably dropped the security software in favor of another solution, which among other security mechanisms puts PowerShell into Constrained Language Mode. This limits the capability of scripts to use WIN32 APIs, hindering attempts to reflectively load compiled executables – making our malware obsolete.
Yoni Zach, information security specialist



sc88 dạo này thấy mọi người nhắc hoài nên mình cũng bấm vào coi thử cho biết, kiểu tò mò giao diện thôi chứ không có ý chơi gì. Vào cái là thấy trang nhìn khá nhẹ mắt, không bị nhét chữ dày đặc nên lướt nhanh cũng dễ chịu. Mình để ý họ chia nội dung thành từng khối rõ ràng, nhìn qua là biết phần nào với phần nào, khỏi phải căng mắt dò. Cái mình thích nữa là menu đặt khá dễ thấy, chuyển qua lại mấy mục không bị vòng vo, cảm giác thao tác mượt. Nói chung hợp kiểu người mới vào xem thử như mình, không cần hiểu gì nhiều vẫn nắm được bố…
Bài viết khá dễ theo dõi, cảm ơn bạn đã chia sẻ. Đoạn giải thích ở giữa đúng cái mình đang thắc mắc bữa giờ. Mình cũng hay xem thống kê XSMB mỗi ngày nên tự gom lại thành một chỗ để tra nhanh khỏi phải tìm nhiều nơi. Ai cần xem số liệu cập nhật theo ngày thì ghé thử https://cloud.anylogic.com/profile/user/1eb0dd6e-b2db-49fe-8390-0a3710acec17
Trước đây mình hay loay hoay cả buổi chỉ để chọn addon Minecraft PE rồi thử ghép với resource pack xem có bị đụng nhau không, vì sợ cài vào là lag hoặc lỗi. Dần dần mình rút kinh nghiệm, ưu tiên mấy shader nhẹ cho máy yếu, xong thỉnh thoảng kiếm thêm vài map mới để đổi gió, chơi đỡ chán. Trong group cũng có người chia sẻ mấy addon kiểu furniture hay alien invasion, có kèm đánh giá sao nên mình đỡ phải tải bừa. Mình thấy mấy thứ này không nên chỉ nghe truyền miệng, quan trọng là nguồn có cập nhật đều. Hôm bữa mình đọc vài gợi ý trên thuvienmc.com nên tiết kiệm thời gian…
b52club14.com dạo này thấy mọi người nhắc hoài nên mình cũng bấm vào coi thử cho biết chứ không có ngồi chơi hay đọc kỹ gì đâu. Vừa vào cái mình để ý ngay là giao diện nhìn khá thoáng, không bị rối mắt kiểu nhét quá nhiều chữ một chỗ. Mấy phần thông tin họ chia theo từng khối rõ ràng nên lướt nhanh vẫn hiểu đang ở mục nào, đỡ phải kéo lên kéo xuống tìm. Mình cũng thích cái cách họ gom menu lại gọn gàng, nằm chỗ dễ thấy nên chuyển trang khá tiện, bấm vài cái là quen tay luôn. Nói chung cảm giác dùng thử vài phút thấy nhẹ nhàng, không bị “ngợp” như…
tải sun win là cái cụm mình thấy lướt đâu cũng gặp nên hôm bữa rảnh mới bấm vào coi thử trang trông ra sao. Mình không có đọc kỹ nội dung hay gì, chủ yếu xem giao diện có dễ chịu không thôi. Cảm giác đầu tiên là trang làm khá thoáng, chia nội dung theo từng khối rõ ràng nên kéo xuống là bắt nhịp được ngay, không bị chữ dồn dập nhìn mệt mắt. Mình cũng để ý phần menu đặt khá dễ thấy, bấm qua lại mấy mục nhanh, không kiểu giấu sâu phải tìm hoài. Nói chung lướt vài phút là hiểu họ sắp xếp thông tin theo nhóm thế nào, nhất là cách họ…