On September 24, 2025, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) sanctioned eight members of Tren de Aragua (TdA) — the Venezuelan transnational criminal organization designated as a Foreign Terrorist Organization — for their role in stealing millions of dollars through ATM jackpotting campaigns across the United States. According to Treasury's announcement, TdA cells physically compromised ATMs and deployed malware to force machines to dispense cash on demand, with losses running into the millions and a demonstrated operational footprint spanning multiple states.
This matters far beyond a sanctions press release. Jackpotting is not a hypothetical or legacy threat — it is a mature, repeatable intrusion methodology that transnational criminal organizations are scaling against U.S. financial infrastructure right now. The TdA case confirms what law enforcement and FS-ISAC have been warning about for years: jackpotting crews are organized, mobile, and increasingly paired with sophisticated malware families such as Ploutus, which has been repeatedly tied to TdA-linked operations. Every bank, credit union, and independent ATM deployer (IAD) with unattended or lobby machines should treat this as an active threat to their fleet.
From a defensive standpoint, jackpotting is uniquely demanding because it blends physical intrusion with endpoint compromise and — in some variants — network pivoting into the ATM switch. Your SOC likely has strong visibility into core banking systems and almost none into the Windows-based PC cores sitting inside your ATMs. That visibility gap is exactly what these crews exploit. This post breaks down how the attack works, what you can realistically detect, and how to harden the fleet.
Technical Analysis
What jackpotting actually looks like in 2026
Modern jackpotting campaigns — including the TdA operations described by Treasury — follow a well-documented attack chain:
-
Reconnaissance and targeting. Crews identify ATMs running outdated or unpatched operating systems (Windows 7/10 IoT builds past support), machines with poorly secured top hats (the upper cabinet housing the PC core), or standalone retail ATMs with known-weak physical locks. Diebold Nixdorf, NCR Atleos, and Hyosung machines are all in scope.
-
Physical access to the PC core. The attacker opens the ATM's upper compartment — often in under a minute with generic tubular lock keys — and gains access to the ATM's internal PC. Two primary techniques follow:
- Malware injection: The attacker connects a USB device or removes/replaces the hard drive with one pre-loaded with jackpotting malware. Ploutus, the family most associated with TdA-linked crews, interacts directly with the ATM's XFS (Extensions for Financial Services) middleware to issue cash-dispense commands to the dispenser, bypassing the cardholder transaction flow entirely.
- Black box attacks: The attacker disconnects the cash dispenser's cable from the ATM PC and attaches a rogue device (often a Raspberry Pi-class board or modified handset) that sends dispense commands directly to the dispenser controller, impersonating a legitimate host session.
-
Cash-out and exfiltration. A money mule triggers the dispense command — via keyboard attached to the infected core, a mobile device paired to the black box, or in some cases remotely if the attacker established persistence and remote access. Machines are emptied of cassettes, often in under ten minutes. Crews rotate across jurisdictions to complicate investigation.
Why this is a security operations problem, not just a physical security problem
Three realities defenders must internalize:
- ATM PC cores are endpoints. They run Windows. They execute binaries, load drivers, and make network connections. Everything your EDR and SIEM do for workstations can — and must — extend to them.
- The XFS layer is the abuse target. Ploutus-class malware does not exploit a memory corruption bug in the classic sense; it abuses the legitimate XFS API (
WFSExecute/dispenser service provider commands) that the ATM application itself uses. That means detection hinges on who is calling the dispenser and from what process, not on signature-matching an exploit. - Network segmentation is frequently weak. An ATM that can reach anything beyond the transaction switch and patch/management infrastructure is an ATM that can become a pivot point into your environment.
No CVE is attached to this campaign, and none should be invented — the technique is architectural abuse combined with physical access, not a single patchable flaw. Exploitation is confirmed active in the wild, with federal law enforcement (FBI, Secret Service) and OFAC action underscoring the scale. There is no CISA KEV entry because there is no single vulnerability; the defensive posture is hardening plus behavioral detection.
Affected scope
- Platforms: Windows-based ATM PC cores across all major manufacturers (Diebold Nixdorf, NCR Atleos, Hyosung/Genmega retail units)
- Software layers: XFS middleware (CEN/XFS standard implementations), vendor ATM application suites, vendor dispenser drivers
- Physical interfaces: USB ports on the PC core, internal SATA (drive swap), dispenser serial/USB cabling (black box insertion)
- At-risk deployers: Financial institutions and IADs running legacy OS builds, machines without full-disk encryption, or fleets without application whitelisting
Detection & Response
The detection philosophy for jackpotting is built on one principle: an ATM PC core is a fixed-function appliance, and fixed-function appliances should have near-zero deviation from a known-good baseline. Any new executable, any USB mass-storage event, any process outside the vendor's application stack, any unexpected network destination is a high-fidelity signal. In a normal enterprise these rules would drown in false positives; on an ATM fleet they should fire almost never — and every firing is worth a dispatch.
Sigma Rules
---
title: Process Execution From Removable Media on ATM Endpoint
id: 3f9a2b71-4c58-4e2a-9d31-7b6c5a8e1f02
status: experimental
description: Detects execution of any binary from removable media paths. On fixed-function ATM PC cores, execution from USB-attached media is a primary jackpotting malware staging indicator (e.g., Ploutus deployment via USB).
references:
- https://home.treasury.gov/news/press-releases
- https://attack.mitre.org/techniques/T1091/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.initial_access
- attack.t1091
logsource:
category: process_creation
product: windows
definition: 'Deploy to ATM PC core hosts only. Not intended for general workstation fleets.'
detection:
selection_path:
Image:
- 'D:\*'
- 'E:\*'
- 'F:\*'
- 'G:\*'
selection_cmd:
CommandLine|contains:
- ':\\'
filter_approved_media:
CommandLine|contains:
- 'D:\vendor_update\'
- 'E:\field_service\'
condition: selection_path and not filter_approved_media
falsepositives:
- Authorized vendor field-service tooling run from approved service media (maintain an allowlist per your ATM vendor's service procedures)
- Scheduled vendor patching executed from removable media under change control
level: critical
---
title: Unexpected Executable Created in ATM Application or XFS Directories
id: 8c14e5a2-77d3-4b6f-a209-3d8f9c4e6b71
status: experimental
description: Detects new executable files written into ATM vendor application directories or XFS middleware paths. Ploutus-class jackpotting malware stages binaries alongside legitimate ATM software to masquerade as vendor components.
references:
- https://attack.mitre.org/techniques/T1036/
- https://www.bleepingcomputer.com/news/security/us-sanctions-tren-de-aragua-members-in-atm-jackpotting-crackdown/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.defense_evasion
- attack.t1036
- attack.persistence
logsource:
category: file_event
product: windows
definition: 'Scope to ATM PC core hosts. Requires Sysmon file creation events or equivalent EDR telemetry.'
detection:
selection:
TargetFilename|contains:
- '\Diebold\'
- '\NCR\'
- '\Aptra\'
- '\Agilis\'
- '\XFS\'
- '\Hyosung\'
TargetFilename|endswith:
- '.exe'
- '.dll'
- '.sys'
filter_updater:
Image|endswith:
- '\updater.exe'
- '\patchmgr.exe'
User|contains: 'SVC_ATM_PATCH'
condition: selection and not filter_updater
falsepositives:
- Vendor software updates applied through the managed patching pipeline (tune Image/User filters to your actual patch management account and tool names)
- Field technician manual installs under an approved work order
level: high
---
title: USB Mass Storage Driver Activation on ATM Endpoint
id: b27d3f90-1a4e-4c85-9f72-6e0a8d2c5b94
status: experimental
description: Detects the USB storage driver (USBSTOR) transitioning to a running state on an ATM PC core, indicating physical connection of a USB mass storage device — a common first step in malware-based jackpotting.
references:
- https://attack.mitre.org/techniques/T1091/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.initial_access
- attack.t1091
logsource:
category: registry_set
product: windows
definition: 'Scope to ATM PC core hosts. Baseline hardening should set USBSTOR Start value to 4 (disabled); any value of 2 or 3 is anomalous.'
detection:
selection:
TargetObject|endswith: '\Services\USBSTOR\Start'
Details:
- 'DWORD (0x00000002)'
- 'DWORD (0x00000003)'
condition: selection
falsepositives:
- Deliberate service maintenance windows where USB storage is temporarily enabled for vendor field service
level: critical
KQL — Microsoft Sentinel / Defender
This hunt correlates process execution from non-standard paths with the fixed-function assumption: an ATM core should only run binaries from its vendor application directories and Windows system paths. Anything else — especially executables launched from user-writable temp paths, removable media, or interactive keyboard sessions outside service windows — is jackpotting-relevant. Assuming ATM devices are tagged or named with a consistent prefix (adapt ATM-* to your naming convention):
// Hunt: anomalous process execution on ATM PC cores
// Assumes ATM devices follow an ATM-* naming convention — adjust to your fleet.
let VendorPaths = dynamic([@"C:\Diebold", @"C:\NCR", @"C:\Program Files\Diebold", @"C:\Program Files\NCR", @"C:\Aptra", @"C:\Windows\System32", @"C:\Windows\SysWOW64", @"C:\Program Files\Windows Defender"]);
DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where DeviceName startswith "ATM-"
| where isnotempty(FolderPath)
| extend InVendorPath = (FolderPath has_any (VendorPaths))
| where InVendorPath == false
| where FolderPath !startswith @"C:\Windows\SoftwareDistribution" // patch noise
| where FolderPath !startswith @"C:\Windows\Installer"
| extend SuspiciousOrigin = case(
FolderPath matches regex @"^[D-Z]:\\", "RemovableMedia",
FolderPath has @"\AppData\", "UserWritablePath",
FolderPath has @"\Temp\", "TempPath",
"NonStandardPath")
| summarize FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), ExecutionCount=count(),
Processes=make_set(ProcessCommandLine, 10), Accounts=make_set(AccountName)
by DeviceName, FileName, FolderPath, SHA256, SuspiciousOrigin
| extend RiskScore = case(
SuspiciousOrigin == "RemovableMedia", 100,
SuspiciousOrigin == "UserWritablePath", 80,
60)
| order by RiskScore desc, FirstSeen asc
// Recommended follow-up: pair with DeviceEvents (ActionType contains 'UsbDriveMount') on the
// same DeviceName within +/- 30 minutes to confirm physical USB staging before process launch.
Velociraptor VQL
Use this artifact during an IR sweep across the ATM fleet to enumerate every executable and DLL resident in ATM application and XFS directories, pull signatures and hashes, and flag anything unsigned or outside the golden-image hash baseline. Feed results into your fleet baseline for diffing.
-- Hunt: Inventory executables/DLLs in ATM vendor directories and flag
-- unsigned or non-baseline binaries (jackpotting malware staging artifact).
-- Deploy against ATM PC core clients only.
LET vendor_globs = [
'C:/Diebold/**/*.exe',
'C:/Diebold/**/*.dll',
'C:/NCR/**/*.exe',
'C:/NCR/**/*.dll',
'C:/Aptra/**/*.exe',
'C:/Program Files/NCR/**/*.exe',
'C:/Program Files/Diebold/**/*.exe',
'C:/XFS/**/*.dll'
]
LET files = SELECT FullPath, Size, Mtime,
hash(path=FullPath) AS Hash,
authenticode(filename=FullPath) AS Signature
FROM foreach(row=vendor_globs,
query={ SELECT FullPath, Size, Mtime FROM glob(globs=_value) })
SELECT FullPath,
Size,
Mtime,
Hash.SHA256 AS SHA256,
Signature.Status AS SignatureStatus,
Signature.Subject AS Signer,
if(condition=Signature.Status =~ 'Trusted' OR Signer =~ 'Diebold|NCR|Microsoft|Hyosung',
then='BASELINE_CANDIDATE', else='INVESTIGATE') AS Verdict
FROM files
ORDER BY Verdict DESC, Mtime DESC
Remediation / Hardening Audit Script
Run this PowerShell audit on ATM PC cores (via your RMM, SCCM, or Velociraptor) to validate the controls that most directly defeat malware-based jackpotting: disk encryption, USB storage lockdown, application whitelisting, and USBSTOR service state. It is audit-only — it reports rather than remediates, so you can review drift before enforcing via GPO.
# ATM Jackpotting Hardening Audit — run elevated on ATM PC cores
# Outputs a compliance report; does not change state. Enforce via GPO/MDM after review.
$report = [ordered]@{}
# 1. Full-disk encryption (defeats offline hard-drive swap / offline malware implantation)
try {
$bde = Get-BitLockerVolume -MountPoint 'C:' -ErrorAction Stop
$report['DiskEncryption'] = "$($bde.VolumeStatus) / Protection: $($bde.ProtectionStatus)"
} catch {
$report['DiskEncryption'] = 'UNKNOWN - BitLocker cmdlets unavailable (check vendor FDE)'
}
# 2. USB mass storage lockdown (USBSTOR Start=4 means disabled)
$usbstor = Get-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Services\USBSTOR' -Name Start -ErrorAction SilentlyContinue
$report['USBSTOR_StartValue'] = if ($usbstor) { $usbstor.Start } else { 'NotFound (default = enabled!)' }
$report['USBStorageBlocked'] = ($usbstor -and $usbstor.Start -eq 4)
# 3. Application whitelisting enforcement (WDAC/Device Guard or AppLocker)
$dg = Get-CimInstance -ClassName Win32_DeviceGuard -Namespace root\Microsoft\Windows\DeviceGuard -ErrorAction SilentlyContinue
$report['WDAC_Enforced'] = if ($dg) { $dg.CodeIntegrityPolicyEnforcementStatus -eq 1 } else { $false }
$applocker = Get-AppLockerPolicy -Effective -ErrorAction SilentlyContinue
$report['AppLocker_Present'] = [bool]$applocker
# 4. Non-Microsoft services and drivers (jackpotting malware persists as services masquerading as vendor tools)
$report['ThirdPartyServices'] = @(Get-CimInstance Win32_Service |
Where-Object { $_.PathName -and $_.PathName -notmatch 'system32|SysWOW64' } |
ForEach-Object { $path = ($_.PathName -replace '^"','').Split(' ')[0].Trim('"')
try { $sig = Get-AuthenticodeSignature $path -ErrorAction Stop; "$($_.Name)|$($sig.Status)|$($sig.SignerCertificate.Subject)" }
catch { "$($_.Name)|SIGNCHECK_FAILED|$path" }
})
# 5. Recent interactive logons outside service accounts (keyboard/console access to the core)
$report['RecentInteractiveLogons'] = @(Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4624; StartTime=(Get-Date).AddDays(-14)} -MaxEvents 500 -ErrorAction SilentlyContinue |
Where-Object { $_.Properties[8].Value -in 2,10 } |
Select-Object -First 20 | ForEach-Object { "$($_.TimeCreated)|$($_.Properties[5].Value)|Type$($_.Properties[8].Value)" })
$report.GetEnumerator() | ForEach-Object { "{0}: {1}" -f $_.Key, ($_.Value -join '; ') }
Remediation
There is no patch for this campaign — the defense is architectural. Prioritize the following, in order:
- Full-disk encryption on every ATM PC core. This is the single most effective control against the dominant TdA technique. If the drive cannot be read offline, the attacker cannot implant malware by swapping or imaging the disk, and a stolen/replaced drive will not boot. Validate TPM presence and enable BitLocker (or the vendor's FDE) fleet-wide.
- Application whitelisting (WDAC or vendor-provided). A fixed-function ATM should execute only signed vendor binaries and OS components. Ploutus and its variants fail outright when arbitrary executables cannot run. Diebold Nixdorf, NCR Atleos, and Hyosung all offer hardened/whitelisted configurations — engage your vendor and reference their current security bulletins.
- Physical controls on the top hat. Replace generic tubular locks with unique-key or electronic locks, install cabinet intrusion switches that alarm to your SOC (not just a local beeper), and add dispenser-cable tamper detection to catch black box insertion. Coordinate alarm telemetry into the SIEM — a top-hat open event at 3:00 a.m. with no corresponding work order is a dispatch trigger.
- USB lockdown. Disable USBSTOR via GPO, physically epoxy or port-lock unused USB ports on the PC core, and require BIOS/UEFI passwords with boot-from-USB disabled.
- Network segmentation. ATM VLANs should reach only the transaction switch endpoints, patch infrastructure, and management plane. Alert on any other egress. Deployer firewalls should deny inbound-initiated sessions to ATM cores entirely.
- Baseline and diff. Build a golden-image hash manifest per ATM model and re-baseline after every vendor update. The Velociraptor artifact above operationalizes this. Jackpotting malware survives because nobody diffs the fleet.
- Monitor the human layer. TdA cash-out relies on mules. Coordinate with your fraud team on ATM surveillance analytics (loitering at the top hat, repeated cassette-emptying events, out-of-hours dispensing with no corresponding host transaction in the switch logs). A dispense event with no matching authorization record from the ATM switch is a definitive jackpotting indicator — build that reconciliation alert if you have not already.
Reporting and coordination: Report suspected jackpotting to the FBI (ic3.gov), the U.S. Secret Service field office (which leads ATM intrusion investigations), and FS-ISAC for peer alerting. Preserve the PC core and any rogue hardware as evidence — do not reimage before law enforcement engages.
Vendor resources: Diebold Nixdorf security advisories, NCR Atleos security guidance, and Hyosung customer security bulletins (accessed via your vendor portal under NDA) — request their current anti-jackpotting hardening packages, which typically bundle FDE enablement, whitelisting profiles, and dispenser authentication firmware. Note that newer dispenser firmware supporting authenticated/encrypted host-to-dispenser sessions materially raises the bar against black box attacks; ask your vendor explicitly about dispenser authentication support for your models.
OFAC's action raises the cost for the crews, but sanctions do not re-encrypt a hard drive or close an open USB port. The organizations that weather this campaign will be the ones that treated their ATM fleet as endpoints worth defending before the top hat was opened.
Related Resources
Security Arsenal Healthcare Cybersecurity AlertMonitor Platform Book a SOC Assessment healthcare Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.