Thursday, February 27, 2025
HomeComputer SecurityATM Robber Malware Turns ATM into Slot Machine to Dispense Cash Automatically

ATM Robber Malware Turns ATM into Slot Machine to Dispense Cash Automatically

Published on

SIEM as a Service

Follow Us on Google News

ATM hijacking malware dubbed WinPot turns the ATMs into a slot machine, which starts dispensing the cash based on SPIN button.

Security researchers from Kaspersky observed the emergence of the WinPot malware, the malware appeared first in the underground markets in March 2018.

Threat actors designed the malware to automatically dispense the cash automatically form the valuable cassettes, researchers call it as ATMPot.

WinPot

WinPot

Attackers designed a clear slot machine-like interface with cassette numbered between 1 to 4 and with a button named SPIN, as soon as the SPIN button is pressed the ATM starts dispensing cash associated with the cassette.

Along with the SPIN button, the interface contains another SCAN button that scans the ATM and update the slots. “We found WinPot to be an amusing and interesting ATM malware family, so we decided to keep a close eye on it”, reads secure list blog post.

The threat actors behind WinPot constantly updating the new samples with modification to evade detection and to track the ATM machines.

The malware also available in underground markets for sale and the price varies between 500 – 1000 USD. Another seller advertised WinPot v.3 along with demo videos and the unidentified called ShowMeMoney, researchers assume that is a new name of WinPot.

WinPot

The ATM cash-out malware mechanism remains the same, but the cybercriminals bring many new modifications.

  • To trick the ATM security systems.
  • To overcome potential ATM limitations.
  • To find ways to keep the money mules from abusing their malware.
  • To improve the interface and error-handling routines.

“We thus expect to see more modifications of the existing ATM malware. The preferred way of protecting the ATM from this sort of threat is to have device control and process whitelisting software running on it,” Kaspersky says.

Related Read

Bank Software Cheif Jailed For Finding a Way to withdraw $1M Free Cash From ATM

Malicious Hackers Steal Money From ATM by Connecting Laptop with ATM Cash Dispenser

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Cisco Nexus Vulnerability Allows Attackers to Inject Malicious Commands

Cisco Systems has issued a critical security advisory for a newly disclosed command injection...

New Wi-Fi Jamming Attack Can Disable Specific Devices

A newly discovered Wi-Fi jamming technique enables attackers to selectively disconnect individual devices from...

GitLab Vulnerabilities Allow Attackers to Bypass Security and Run Arbitrary Scripts

GitLab has urgently released security updates to address multiple high-severity vulnerabilities in its platform...

LibreOffice Flaws Allow Attackers to Run Malicious Files on Windows

A high-severity security vulnerability (CVE-2025-0514) in LibreOffice, the widely used open-source office suite, has...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Cisco Nexus Vulnerability Allows Attackers to Inject Malicious Commands

Cisco Systems has issued a critical security advisory for a newly disclosed command injection...

New Wi-Fi Jamming Attack Can Disable Specific Devices

A newly discovered Wi-Fi jamming technique enables attackers to selectively disconnect individual devices from...

GitLab Vulnerabilities Allow Attackers to Bypass Security and Run Arbitrary Scripts

GitLab has urgently released security updates to address multiple high-severity vulnerabilities in its platform...