ATM JACKPOTTING (PLOUTUS): The Complete Carder's Field Manual

Professor

Professional
Messages
1,814
Reaction score
1,787
Points
113
From the desk of an carder with over a decade in the game

TABLE OF CONTENTS
  • Introduction: The Loudest Game in the Underground
  • Part 1: What ATM Jackpotting Actually Is
  • Part 2: The Technical Anatomy of Ploutus
  • Part 3: The Attack Methodology — Step by Step
  • Part 4: The Physical Security Layer — Keys, Locks, and Sensors
  • Part 5: Comparison of Jackpotting vs. Other Cashout Methods
  • Part 6: Why This Is Not a Solo Game
  • Part 7: OPSEC — What Gets Teams Caught
  • Part 8: Common Mistakes and How to Fix Them
  • Part 9: Complete Checklist
  • Part 10: Key Takeaways

INTRODUCTION: THE LOUDEST GAME IN THE UNDERGROUND​

Bro, let's get one thing straight from the jump: ATM jackpotting is not carding. It's not account takeover. It's not a quiet digital carding that you can run from a laptop in your mother's basement.
ATM jackpotting is a bank robbery with a keyboard. It's a physical intrusion into a machine that holds the bank's cash, followed by a software attack that forces the machine to empty its cassettes.
If you're reading this because you saw a YouTube video of Barnaby Jack making an ATM spit cash at Black Hat 2010 and thought "I want to do that" — understand what you're walking into. This is a game with physical risk, federal charges, and prison sentences measured in decades.
This manual is not an encouragement. It's a field guide to understanding the threat model — how the attacks work, why they fail, and what law enforcement and banks are doing to stop them.

PART 1: WHAT ATM JACKPOTTING ACTUALLY IS​

1.1. The Definition​

ATM jackpotting is a cyber-physical attack in which carders compromise an ATM's internal systems and force the cash dispenser to release all stored currency — without a legitimate card, customer account, or bank authorization.
Unlike skimming, which targets customer card data, jackpotting targets the machine itself. The goal is not to steal identities. The goal is to steal the physical cash inside the ATM.

1.2. The Two Families of Jackpotting​

TypeMethodAttribution
Physical JackpottingCarders opens ATM cabinet, installs malware (Ploutus, Cutlet Maker, WinPot), forces dispenser to emptyOrganized carder's groups, Tren de Aragua
Network Cash-OutAttacker compromises bank's payment switch, forges ISO 8583 approval messages, mule cards withdraw cashNation-state (Lazarus/APT38), high sophistication

Physical jackpotting is what we're covering here. It's the method used by Tren de Aragua and the one that's caused the current crisis.

1.3. The Scale of the Problem​

The numbers are staggering:
  • 1,900+ incidents since 2020 in the US
  • 700+ incidents in 2025 alone
  • $20+ million in losses in 2025
  • $40.73 million in total losses from one Tren de Aragua campaign involving 1,500 attacks
  • 93 defendants charged in the DOJ's jackpotting crackdown
  • $100,000+ loss per successful attempt

This is not a niche technique. It's an industrial-scale carding operation.

PART 2: THE TECHNICAL ANATOMY OF PLOUTUS​

2.1. The XFS Vulnerability​

The core of the Ploutus attack is an exploitation of the XFS (eXtensions for Financial Services) API layer.

Here's how it works:
When a legitimate ATM transaction occurs, the ATM application sends instructions through XFS to the bank's authorization system. The bank approves or declines, and the cash dispenser acts accordingly.
Ploutus exploits this by issuing its own commands directly to XFS. By bypassing the bank authorization layer entirely, the malware can instruct the cash dispenser to release money on demand.
As the explained: "If a threat actor can issue their own commands to XFS, they can bypass bank authorization entirely and instruct the ATM to dispense cash on demand".

2.2. Why It Works Across Manufacturers​

One of the most dangerous aspects of Ploutus is its manufacturer-agnostic design. The noted that "the malware can be used across ATMs of different manufacturers with very little adjustment to the code as the Windows operating system is exploited during the compromise".
This means a single malware variant can target Diebold, NCR, Triton, and other ATM brands — as long as they run on Windows.

2.3. The Activation Methods​

Ploutus has evolved over time. Different versions use different activation methods:
VersionActivation Method
Early PloutusExternal keyboard connected to the ATM
Ploutus.DSMS message to a phone connected to the ATM
Modern VariantsOne-time codes, remote commands, external devices

The Tren de Aragua indictment describes a sophisticated operation: "The Ploutus malware's primary purpose was to issue unauthorized commands associated with the Cash Dispensing Module of the ATM in order to force withdrawals of currency".

2.4. The Anti-Forensic Features​

Modern Ploutus variants include evidence deletion capabilities designed to "conceal, create a false impression, mislead, or otherwise deceive employees of the banks and credit unions from learning about the deployment of the malware on the ATM".
This is why jackpotting is often not detected until after the cash is gone.

PART 3: THE ATTACK METHODOLOGY — STEP BY STEP​

Based on the DOJ indictment and advisories, here is the documented attack methodology used by Tren de Aragua and similar groups:

Step 1: Reconnaissance​

The group travels to target locations and conducts initial reconnaissance. They take note of external security features — cameras, lighting, proximity to law enforcement, foot traffic.
They specifically target ATMs they believe are more vulnerable to malware — often older models running outdated Windows versions.

Step 2: Physical Access​

The group opens the hood or door of the ATM using generic keys that are widely available for purchase online.
The noted: "Typically, threat actors deploy malware such as the Ploutus variant to exploit the XFS API... After opening up the front of an ATM with 'generic keys'".

Step 3: Alarm Check​

After opening the ATM, the group waits nearby to see if they triggered an alarm or law enforcement response.
In the Kansas case, the attempted malware installation triggered an alarm, and law enforcement responded. The perpetrators fled and did not return.

Step 4: Malware Installation​

There are three documented methods for installing the malware :
MethodDescription
Hard Drive RemovalRemove the ATM's hard drive, install malware directly, return it to the machine
Hard Drive SwapReplace the original hard drive with one pre-loaded with Ploutus
External DeviceConnect an external device (e.g., thumb drive, Raspberry Pi) that deploys the malware

Step 5: Reboot and Activation​

After the malware is installed, the ATM is rebooted. The malware activates — either via SMS, one-time code, or remote command — and forces the dispenser to release cash.
The noted: "The malware interacts directly with the ATM hardware, bypassing any communications or security of the original ATM software. The malware does not require connection to an actual bank customer account to dispense cash".

Step 6: Cash Collection​

The group returns to collect the dispensed cash. The entire process — from installation to cash-out — can occur in minutes.

Step 7: Fund Distribution​

The proceeds are split in predetermined portions among conspiracy members. In the Tren de Aragua case, the money was "transferred among its members and associates to conceal the illegally obtained cash".

PART 4: THE PHYSICAL SECURITY LAYER — KEYS, LOCKS, AND SENSORS​

4.1. The Generic Key Problem​

The single biggest vulnerability in physical jackpotting is the use of generic keys that can be purchased online.
The explicitly recommends: "Changing the standard locks on ATM devices to prevent the use of keys available for purchase online".

4.2. The Industry Response​

The ATM industry is responding with connected, keyless lock systems:
dormakaba Apexx Strato Rotary — a keyless electronic lock that replaces shared mechanical keys with Bluetooth Low Energy (BLE) credentials managed through a mobile app.

Key features:
  • Keyless access: No physical keys to steal or copy
  • Controlled technician access: Digital credentials assigned to individual users
  • Automatic audit capture: Every access event recorded
  • Real-time monitoring: Door and latch status confirmation
  • Centralized management: Remote permission updates

As dormakaba noted: "You can't steal or copy a key that no longer exists".

4.3. Additional Physical Mitigations​

The FLASH advisory recommends:
MitigationDescription
Threat SensorsVibration, temperature change sensors to alert security
KeypadsDevices that set off alarms if a code isn't entered when the maintenance hatch opens
Physical BarriersAdditional keyed barriers preventing access to cashbox and maintenance hatch
Security CamerasCoverage of necessary areas with preserved footage

4.4. Software Mitigations​

Also recommends software-level defenses:
MitigationDescription
Device WhitelistingPrevents connection of unauthorized devices (phones, hard drives)
Firmware Integrity ChecksDigital signatures using Trusted Platform Module (TPM)
Hard Drive EncryptionPrevents malware introduction to an unplugged hard drive
Audit Removable StorageEnable auditing under Object Access
Gold Image BaselinesVerified system images to detect unauthorized changes

PART 5: COMPARISON OF JACKPOTTING VS. OTHER CASHOUT METHODS​

FactorATM JackpottingBank Log CashoutCarding (CNP)
Physical RiskExtremeLowNone
Skill RequiredHigh (physical + technical)MediumLow
Team RequiredYes (recon, install, collect)NoNo
Detection SpeedMinutes to hoursHours to daysImmediate
Loss per Attempt$100,000+$3,000-5,000$100-1,000

The conclusion is obvious: ATM jackpotting has the highest risk, highest penalty, and highest law enforcement priority of any cashout method. It's not comparable to carding or bank log cashout.

PART 6: WHY THIS IS NOT A SOLO GAME​

The DOJ indictments make clear that jackpotting requires a coordinated team:
  • Reconnaissance specialists — identify vulnerable ATMs, note security features
  • Physical access carders — open the ATM, install malware, avoid alarms
  • Technical carders — manage the malware, activate the command
  • Cash collectors — retrieve the dispensed money
  • Money launderers — distribute proceeds, convert to crypto

The Tren de Aragua operation used multiple vehicles, coordinated travel, and predetermined splits.
This is organized carding territory. If you're a solo carder, you have no business attempting this.

PART 7: OPSEC — WHAT GETS TEAMS CAUGHT​

Based on the DOJ cases, here's what led to arrests:
MistakeConsequence
Triggering alarmsLaw enforcement response, surveillance footage
Returning to the sceneArrest days later
Using vehiclesLicense plate capture, traffic cameras
Leaving forensic evidenceCounterfeit keys, drill marks, DNA
Crashing vehiclesDeath and arrest
Associating with TdATerrorism enhancement, 335-year maximum

The most important OPSEC lesson: The Kansas and Michigan cases both involved alarms triggering. The recommended mitigation is literally to shut down the ATM when jackpotting IOCs are detected. Banks are implementing this.

PART 8: COMMON MISTAKES AND HOW TO FIX THEM​

Mistake 1: Targeting ATMs with Generic Locks​

Problem: Generic keys are widely available, making these ATMs easy targets.
Fix: Banks are replacing these with keyless locks. You can't fix this — you can only avoid targeting updated machines.

Mistake 2: Ignoring Alarm Systems​

Problem: Alarm triggers lead to immediate law enforcement response.
Fix: There is no fix. Modern ATMs have vibration, temperature, and door sensors. If you trigger one, you're done.

Mistake 3: Not Having a Clean Exit​

Problem: Surveillance cameras capture vehicles and faces.
Fix: This requires extensive planning (multiple vehicles, routes, disguises). It's beyond solo capability.

Mistake 4: Leaving Evidence​

Problem: Counterfeit keys, drill marks, and DNA have all been used in prosecutions.
Fix: This requires forensic-level planning. Again, not solo work.

Mistake 5: Associating with Terrorist Organizations​

Problem: TdA association triggers material support to terrorism charges with 335-year maximums.
Fix: Don't associate with terrorist organizations. This is not negotiable.

PART 9: COMPLETE CHECKLIST​

If You're Considering This (You Shouldn't Be)​

  • □ Do you have a team of at least 5 people?
  • □ Do you have a vehicle fleet with clean plates?
  • □ Do you have reconnaissance capability?
  • □ Do you have technical capability to deploy and activate Ploutus?
  • □ Do you have a money laundering network?
  • □ Are you prepared for federal bank larceny charges?
  • □ Are you prepared for a terrorism enhancement?
  • □ Are you prepared for decades in prison?

What Banks Are Doing (To Stop You)​

  • □ Replacing generic locks with keyless systems
  • □ Installing vibration/temperature sensors
  • □ Implementing device whitelisting
  • □ Enabling hard drive encryption
  • □ Using gold image baselines
  • □ Configuring automatic shutdown on jackpotting IOCs

PART 10: KEY TAKEAWAYS​

Bro, here's the bottom line:
  1. ATM jackpotting is bank robbery, not carding. It's a physical intrusion followed by a software attack. The penalties reflect that.
  2. Ploutus exploits the XFS layer to bypass bank authorization and command the cash dispenser directly.
  3. The attack requires physical access — opening the ATM with generic keys, installing malware, rebooting.
  4. The industry is fighting back — keyless locks, sensors, whitelisting, encryption, and automatic shutdown on IOCs.
  5. This is not a solo game. Every documented case involves teams, vehicles, coordination, and money laundering.
  6. The detection window is closing. Alarms trigger response. Cameras capture faces. Forensics capture DNA.

The golden rule for 2026: If you're reading this and thinking "I can do this," you can't. This is organized carders with organized carding consequences. Stay in your lane.

Good luck, bro. If you need more — ask.
 
Top