ATMSpitter
- Malware type
- trojan
- Family
- Malware family
- Profile updated
- 2026-07-07 12:51:07
Targeted industries: financial-services
Context
The ATMSpitter family consists of command-line tools designed to control the cash dispenser of an ATM through function calls to either CSCWCNG.dll or MFSXFS.dll. Both libraries are legitimate Windows drivers used to interact with the components of different ATM models.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Atmspitter_Auto (yara-rule)
Reports & references
- secureworks.com — Gold Kingswood (report)
- secureworks.com — Gold Kingswood (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Atmspitter (report)
- quoscient.io — Quoint Intbri Atmspitter V2 (report)
- quoscient.io — Quoint Intbri New Atmspitter (report)