Professor
Professional
- Messages
- 1,814
- Reaction score
- 1,787
- Points
- 113
From the desk of an carder with over a decade in the game
TABLE OF CONTENTS
ATM jackpotting is a bank robbery with a keyboard. It's a physical intrusion into a machine that holds the bank's cash, followed by a software attack that forces the machine to empty its cassettes.
If you're reading this because you saw a YouTube video of Barnaby Jack making an ATM spit cash at Black Hat 2010 and thought "I want to do that" — understand what you're walking into. This is a game with physical risk, federal charges, and prison sentences measured in decades.
This manual is not an encouragement. It's a field guide to understanding the threat model — how the attacks work, why they fail, and what law enforcement and banks are doing to stop them.
Unlike skimming, which targets customer card data, jackpotting targets the machine itself. The goal is not to steal identities. The goal is to steal the physical cash inside the ATM.
Physical jackpotting is what we're covering here. It's the method used by Tren de Aragua and the one that's caused the current crisis.
This is not a niche technique. It's an industrial-scale carding operation.
Here's how it works:
When a legitimate ATM transaction occurs, the ATM application sends instructions through XFS to the bank's authorization system. The bank approves or declines, and the cash dispenser acts accordingly.
Ploutus exploits this by issuing its own commands directly to XFS. By bypassing the bank authorization layer entirely, the malware can instruct the cash dispenser to release money on demand.
As the explained: "If a threat actor can issue their own commands to XFS, they can bypass bank authorization entirely and instruct the ATM to dispense cash on demand".
This means a single malware variant can target Diebold, NCR, Triton, and other ATM brands — as long as they run on Windows.
The Tren de Aragua indictment describes a sophisticated operation: "The Ploutus malware's primary purpose was to issue unauthorized commands associated with the Cash Dispensing Module of the ATM in order to force withdrawals of currency".
This is why jackpotting is often not detected until after the cash is gone.
They specifically target ATMs they believe are more vulnerable to malware — often older models running outdated Windows versions.
The noted: "Typically, threat actors deploy malware such as the Ploutus variant to exploit the XFS API... After opening up the front of an ATM with 'generic keys'".
In the Kansas case, the attempted malware installation triggered an alarm, and law enforcement responded. The perpetrators fled and did not return.
The noted: "The malware interacts directly with the ATM hardware, bypassing any communications or security of the original ATM software. The malware does not require connection to an actual bank customer account to dispense cash".
The explicitly recommends: "Changing the standard locks on ATM devices to prevent the use of keys available for purchase online".
dormakaba Apexx Strato Rotary — a keyless electronic lock that replaces shared mechanical keys with Bluetooth Low Energy (BLE) credentials managed through a mobile app.
Key features:
As dormakaba noted: "You can't steal or copy a key that no longer exists".
The conclusion is obvious: ATM jackpotting has the highest risk, highest penalty, and highest law enforcement priority of any cashout method. It's not comparable to carding or bank log cashout.
The Tren de Aragua operation used multiple vehicles, coordinated travel, and predetermined splits.
This is organized carding territory. If you're a solo carder, you have no business attempting this.
The most important OPSEC lesson: The Kansas and Michigan cases both involved alarms triggering. The recommended mitigation is literally to shut down the ATM when jackpotting IOCs are detected. Banks are implementing this.
Fix: Banks are replacing these with keyless locks. You can't fix this — you can only avoid targeting updated machines.
Fix: There is no fix. Modern ATMs have vibration, temperature, and door sensors. If you trigger one, you're done.
Fix: This requires extensive planning (multiple vehicles, routes, disguises). It's beyond solo capability.
Fix: This requires forensic-level planning. Again, not solo work.
Fix: Don't associate with terrorist organizations. This is not negotiable.
The golden rule for 2026: If you're reading this and thinking "I can do this," you can't. This is organized carders with organized carding consequences. Stay in your lane.
Good luck, bro. If you need more — ask.
TABLE OF CONTENTS
- Introduction: The Loudest Game in the Underground
- Part 1: What ATM Jackpotting Actually Is
- Part 2: The Technical Anatomy of Ploutus
- Part 3: The Attack Methodology — Step by Step
- Part 4: The Physical Security Layer — Keys, Locks, and Sensors
- Part 5: Comparison of Jackpotting vs. Other Cashout Methods
- Part 6: Why This Is Not a Solo Game
- Part 7: OPSEC — What Gets Teams Caught
- Part 8: Common Mistakes and How to Fix Them
- Part 9: Complete Checklist
- Part 10: Key Takeaways
INTRODUCTION: THE LOUDEST GAME IN THE UNDERGROUND
Bro, let's get one thing straight from the jump: ATM jackpotting is not carding. It's not account takeover. It's not a quiet digital carding that you can run from a laptop in your mother's basement.ATM jackpotting is a bank robbery with a keyboard. It's a physical intrusion into a machine that holds the bank's cash, followed by a software attack that forces the machine to empty its cassettes.
If you're reading this because you saw a YouTube video of Barnaby Jack making an ATM spit cash at Black Hat 2010 and thought "I want to do that" — understand what you're walking into. This is a game with physical risk, federal charges, and prison sentences measured in decades.
This manual is not an encouragement. It's a field guide to understanding the threat model — how the attacks work, why they fail, and what law enforcement and banks are doing to stop them.
PART 1: WHAT ATM JACKPOTTING ACTUALLY IS
1.1. The Definition
ATM jackpotting is a cyber-physical attack in which carders compromise an ATM's internal systems and force the cash dispenser to release all stored currency — without a legitimate card, customer account, or bank authorization.Unlike skimming, which targets customer card data, jackpotting targets the machine itself. The goal is not to steal identities. The goal is to steal the physical cash inside the ATM.
1.2. The Two Families of Jackpotting
| Type | Method | Attribution |
|---|---|---|
| Physical Jackpotting | Carders opens ATM cabinet, installs malware (Ploutus, Cutlet Maker, WinPot), forces dispenser to empty | Organized carder's groups, Tren de Aragua |
| Network Cash-Out | Attacker compromises bank's payment switch, forges ISO 8583 approval messages, mule cards withdraw cash | Nation-state (Lazarus/APT38), high sophistication |
Physical jackpotting is what we're covering here. It's the method used by Tren de Aragua and the one that's caused the current crisis.
1.3. The Scale of the Problem
The numbers are staggering:- 1,900+ incidents since 2020 in the US
- 700+ incidents in 2025 alone
- $20+ million in losses in 2025
- $40.73 million in total losses from one Tren de Aragua campaign involving 1,500 attacks
- 93 defendants charged in the DOJ's jackpotting crackdown
- $100,000+ loss per successful attempt
This is not a niche technique. It's an industrial-scale carding operation.
PART 2: THE TECHNICAL ANATOMY OF PLOUTUS
2.1. The XFS Vulnerability
The core of the Ploutus attack is an exploitation of the XFS (eXtensions for Financial Services) API layer.Here's how it works:
When a legitimate ATM transaction occurs, the ATM application sends instructions through XFS to the bank's authorization system. The bank approves or declines, and the cash dispenser acts accordingly.
Ploutus exploits this by issuing its own commands directly to XFS. By bypassing the bank authorization layer entirely, the malware can instruct the cash dispenser to release money on demand.
As the explained: "If a threat actor can issue their own commands to XFS, they can bypass bank authorization entirely and instruct the ATM to dispense cash on demand".
2.2. Why It Works Across Manufacturers
One of the most dangerous aspects of Ploutus is its manufacturer-agnostic design. The noted that "the malware can be used across ATMs of different manufacturers with very little adjustment to the code as the Windows operating system is exploited during the compromise".This means a single malware variant can target Diebold, NCR, Triton, and other ATM brands — as long as they run on Windows.
2.3. The Activation Methods
Ploutus has evolved over time. Different versions use different activation methods:| Version | Activation Method |
|---|---|
| Early Ploutus | External keyboard connected to the ATM |
| Ploutus.D | SMS message to a phone connected to the ATM |
| Modern Variants | One-time codes, remote commands, external devices |
The Tren de Aragua indictment describes a sophisticated operation: "The Ploutus malware's primary purpose was to issue unauthorized commands associated with the Cash Dispensing Module of the ATM in order to force withdrawals of currency".
2.4. The Anti-Forensic Features
Modern Ploutus variants include evidence deletion capabilities designed to "conceal, create a false impression, mislead, or otherwise deceive employees of the banks and credit unions from learning about the deployment of the malware on the ATM".This is why jackpotting is often not detected until after the cash is gone.
PART 3: THE ATTACK METHODOLOGY — STEP BY STEP
Based on the DOJ indictment and advisories, here is the documented attack methodology used by Tren de Aragua and similar groups:Step 1: Reconnaissance
The group travels to target locations and conducts initial reconnaissance. They take note of external security features — cameras, lighting, proximity to law enforcement, foot traffic.They specifically target ATMs they believe are more vulnerable to malware — often older models running outdated Windows versions.
Step 2: Physical Access
The group opens the hood or door of the ATM using generic keys that are widely available for purchase online.The noted: "Typically, threat actors deploy malware such as the Ploutus variant to exploit the XFS API... After opening up the front of an ATM with 'generic keys'".
Step 3: Alarm Check
After opening the ATM, the group waits nearby to see if they triggered an alarm or law enforcement response.In the Kansas case, the attempted malware installation triggered an alarm, and law enforcement responded. The perpetrators fled and did not return.
Step 4: Malware Installation
There are three documented methods for installing the malware :| Method | Description |
|---|---|
| Hard Drive Removal | Remove the ATM's hard drive, install malware directly, return it to the machine |
| Hard Drive Swap | Replace the original hard drive with one pre-loaded with Ploutus |
| External Device | Connect an external device (e.g., thumb drive, Raspberry Pi) that deploys the malware |
Step 5: Reboot and Activation
After the malware is installed, the ATM is rebooted. The malware activates — either via SMS, one-time code, or remote command — and forces the dispenser to release cash.The noted: "The malware interacts directly with the ATM hardware, bypassing any communications or security of the original ATM software. The malware does not require connection to an actual bank customer account to dispense cash".
Step 6: Cash Collection
The group returns to collect the dispensed cash. The entire process — from installation to cash-out — can occur in minutes.Step 7: Fund Distribution
The proceeds are split in predetermined portions among conspiracy members. In the Tren de Aragua case, the money was "transferred among its members and associates to conceal the illegally obtained cash".PART 4: THE PHYSICAL SECURITY LAYER — KEYS, LOCKS, AND SENSORS
4.1. The Generic Key Problem
The single biggest vulnerability in physical jackpotting is the use of generic keys that can be purchased online.The explicitly recommends: "Changing the standard locks on ATM devices to prevent the use of keys available for purchase online".
4.2. The Industry Response
The ATM industry is responding with connected, keyless lock systems:dormakaba Apexx Strato Rotary — a keyless electronic lock that replaces shared mechanical keys with Bluetooth Low Energy (BLE) credentials managed through a mobile app.
Key features:
- Keyless access: No physical keys to steal or copy
- Controlled technician access: Digital credentials assigned to individual users
- Automatic audit capture: Every access event recorded
- Real-time monitoring: Door and latch status confirmation
- Centralized management: Remote permission updates
As dormakaba noted: "You can't steal or copy a key that no longer exists".
4.3. Additional Physical Mitigations
The FLASH advisory recommends:| Mitigation | Description |
|---|---|
| Threat Sensors | Vibration, temperature change sensors to alert security |
| Keypads | Devices that set off alarms if a code isn't entered when the maintenance hatch opens |
| Physical Barriers | Additional keyed barriers preventing access to cashbox and maintenance hatch |
| Security Cameras | Coverage of necessary areas with preserved footage |
4.4. Software Mitigations
Also recommends software-level defenses:| Mitigation | Description |
|---|---|
| Device Whitelisting | Prevents connection of unauthorized devices (phones, hard drives) |
| Firmware Integrity Checks | Digital signatures using Trusted Platform Module (TPM) |
| Hard Drive Encryption | Prevents malware introduction to an unplugged hard drive |
| Audit Removable Storage | Enable auditing under Object Access |
| Gold Image Baselines | Verified system images to detect unauthorized changes |
PART 5: COMPARISON OF JACKPOTTING VS. OTHER CASHOUT METHODS
| Factor | ATM Jackpotting | Bank Log Cashout | Carding (CNP) |
|---|---|---|---|
| Physical Risk | Extreme | Low | None |
| Skill Required | High (physical + technical) | Medium | Low |
| Team Required | Yes (recon, install, collect) | No | No |
| Detection Speed | Minutes to hours | Hours to days | Immediate |
| Loss per Attempt | $100,000+ | $3,000-5,000 | $100-1,000 |
The conclusion is obvious: ATM jackpotting has the highest risk, highest penalty, and highest law enforcement priority of any cashout method. It's not comparable to carding or bank log cashout.
PART 6: WHY THIS IS NOT A SOLO GAME
The DOJ indictments make clear that jackpotting requires a coordinated team:- Reconnaissance specialists — identify vulnerable ATMs, note security features
- Physical access carders — open the ATM, install malware, avoid alarms
- Technical carders — manage the malware, activate the command
- Cash collectors — retrieve the dispensed money
- Money launderers — distribute proceeds, convert to crypto
The Tren de Aragua operation used multiple vehicles, coordinated travel, and predetermined splits.
This is organized carding territory. If you're a solo carder, you have no business attempting this.
PART 7: OPSEC — WHAT GETS TEAMS CAUGHT
Based on the DOJ cases, here's what led to arrests:| Mistake | Consequence |
|---|---|
| Triggering alarms | Law enforcement response, surveillance footage |
| Returning to the scene | Arrest days later |
| Using vehicles | License plate capture, traffic cameras |
| Leaving forensic evidence | Counterfeit keys, drill marks, DNA |
| Crashing vehicles | Death and arrest |
| Associating with TdA | Terrorism enhancement, 335-year maximum |
The most important OPSEC lesson: The Kansas and Michigan cases both involved alarms triggering. The recommended mitigation is literally to shut down the ATM when jackpotting IOCs are detected. Banks are implementing this.
PART 8: COMMON MISTAKES AND HOW TO FIX THEM
Mistake 1: Targeting ATMs with Generic Locks
Problem: Generic keys are widely available, making these ATMs easy targets.Fix: Banks are replacing these with keyless locks. You can't fix this — you can only avoid targeting updated machines.
Mistake 2: Ignoring Alarm Systems
Problem: Alarm triggers lead to immediate law enforcement response.Fix: There is no fix. Modern ATMs have vibration, temperature, and door sensors. If you trigger one, you're done.
Mistake 3: Not Having a Clean Exit
Problem: Surveillance cameras capture vehicles and faces.Fix: This requires extensive planning (multiple vehicles, routes, disguises). It's beyond solo capability.
Mistake 4: Leaving Evidence
Problem: Counterfeit keys, drill marks, and DNA have all been used in prosecutions.Fix: This requires forensic-level planning. Again, not solo work.
Mistake 5: Associating with Terrorist Organizations
Problem: TdA association triggers material support to terrorism charges with 335-year maximums.Fix: Don't associate with terrorist organizations. This is not negotiable.
PART 9: COMPLETE CHECKLIST
If You're Considering This (You Shouldn't Be)
- □ Do you have a team of at least 5 people?
- □ Do you have a vehicle fleet with clean plates?
- □ Do you have reconnaissance capability?
- □ Do you have technical capability to deploy and activate Ploutus?
- □ Do you have a money laundering network?
- □ Are you prepared for federal bank larceny charges?
- □ Are you prepared for a terrorism enhancement?
- □ Are you prepared for decades in prison?
What Banks Are Doing (To Stop You)
- □ Replacing generic locks with keyless systems
- □ Installing vibration/temperature sensors
- □ Implementing device whitelisting
- □ Enabling hard drive encryption
- □ Using gold image baselines
- □ Configuring automatic shutdown on jackpotting IOCs
PART 10: KEY TAKEAWAYS
Bro, here's the bottom line:- ATM jackpotting is bank robbery, not carding. It's a physical intrusion followed by a software attack. The penalties reflect that.
- Ploutus exploits the XFS layer to bypass bank authorization and command the cash dispenser directly.
- The attack requires physical access — opening the ATM with generic keys, installing malware, rebooting.
- The industry is fighting back — keyless locks, sensors, whitelisting, encryption, and automatic shutdown on IOCs.
- This is not a solo game. Every documented case involves teams, vehicles, coordination, and money laundering.
- The detection window is closing. Alarms trigger response. Cameras capture faces. Forensics capture DNA.
The golden rule for 2026: If you're reading this and thinking "I can do this," you can't. This is organized carders with organized carding consequences. Stay in your lane.
Good luck, bro. If you need more — ask.