JavaDispCash

Malware type
trojan
Profile updated
2026-07-07 14:32:13

Targeted industries: financial-services

Context

JavaDispCash is a piece of malware designed for ATMs. The compromise happens by using the JVM attach-API on the ATM's local application and the goal is to remotely control its operation. The malware's primary feature is the ability to dispense cash. The malware also spawns a local port (65413) listening for commands from the attacker which needs to be located in the same internal network.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Jar.Javadispcash (report)
  • github.com — Libertad Y Gloria A Mexican Cyber Heist Story Cybercrimecon19 Singapore (report)
  • twitter.com — 1111254169623674882 (report)

External references