By Tanveer Ahmed :
A sophisticated malware strain targeting Automated Teller Machines (ATMs) is spreading globally, enabling hackers to remotely force machines to dispense cash without any interaction with customer accounts, according to a new security advisory.
The malware, identified as “Ploutus,” has prompted warnings from 1LINK, Pakistan’s premier financial switch operator, which has circulated an alert to all scheduled banks across the country urging immediate preventive action.
How the Attack Works
Unlike conventional cyberattacks that target banking networks or customer data, Ploutus gives attackers direct control over the ATM hardware itself. Security experts explain that the malware allows criminals to gain physical access to machines using commonly available generic keys.
Deployment occurs either by copying the malicious software onto the ATM’s storage device or by replacing the storage device entirely with an infected one. Once installed, Ploutus bypasses standard security safeguards, leaving machines highly vulnerable to unauthorized cash withdrawals.
The malware’s design allows it to be adapted across different ATM manufacturers with minimal modifications, making it a versatile threat to the global banking infrastructure.
Warning Signs
The advisory lists several indicators that an ATM may be compromised. These include suspicious .exe files appearing on the system, unauthorized remote access applications, abnormal autorun configurations, and custom services running without authorization.
Physical warning signs include ATM doors being opened outside scheduled maintenance windows and hard drives being removed from machines without official approval.
For ATMs running Windows operating systems, specific digital indicators have been identified, though detailed technical signatures remain restricted to banking security teams.
Recommended Defenses
To counter the growing threat, the advisory outlines comprehensive mitigation measures across multiple security domains:
On the physical front, banks are urged to upgrade locks, install additional sensors and cameras, erect barriers around ATMs, and closely monitor any unusual access attempts.
Hardware-level protections include enabling disk encryption, implementing firmware integrity checks, activating memory protection, maintaining device whitelisting, and configuring automatic shutdown protocols when malware is detected.
Logical access controls require disabling external storage interfaces by default, allowing only approved access with continuous monitoring. Network security measures involve IP whitelisting, endpoint detection implementation, and restricting software execution through whitelisting policies.
The advisory also stresses the importance of robust logging and auditing. Banks should enable advanced audit policies to detect unauthorized file access or USB connections, maintain centralized logs, and conduct regular audits of all ATM devices.
Prevention practices highlighted include changing default credentials immediately upon deployment, maintaining trusted “gold images” of ATM systems, and conducting thorough security assessments in preproduction environments before any new machine goes live.
Urgent Warning
The advisory warns that without swift implementation of these measures, Ploutus could lead to large-scale ATM “jackpotting” incidents—where machines are forced to eject their entire cash cassettes—posing significant financial risks to both banking institutions and their customers.
The alert comes as part of broader international efforts to coordinate responses to the evolving malware threat, which has already been detected in multiple countries. Banks across Pakistan have been instructed to review their ATM security protocols urgently.






