ATMSpitter

Malware type
trojan
Family
Malware family
Profile updated
2026-07-07 12:51:07

Targeted industries: financial-services

Context

The ATMSpitter family consists of command-line tools designed to control the cash dispenser of an ATM through function calls to either CSCWCNG.dll or MFSXFS.dll. Both libraries are legitimate Windows drivers used to interact with the components of different ATM models.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Atmspitter_Auto (yara-rule)

Reports & references

  • secureworks.com — Gold Kingswood (report)
  • secureworks.com — Gold Kingswood (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Atmspitter (report)
  • quoscient.io — Quoint Intbri Atmspitter V2 (report)
  • quoscient.io — Quoint Intbri New Atmspitter (report)

External references