Alpha Cyber

Exposing Alice ATM Stealer: Infrastructure Mapping of a Financial Threat

Financial institutions remain top targets for cybercriminal groups focused on high-reward operations.

Alpha Cyber Research2 min readupdated 1 Apr 2026
Alice ATM Stealer

Financial institutions remain top targets for cybercriminal groups focused on high-reward operations. One such malware family, Alice ATM Stealer, is designed specifically to compromise ATM systems, allowing attackers to dispense cash, bypassing legitimate banking processes.

Our security analysts have mapped the infrastructure behind a recent campaign involving Alice ATM Stealer, uncovering how cybercriminals structure, distribute, and manage these attacks. This mapping enables us to detect and disrupt malicious operations before they impact your organization.

Threat Overview

Alice ATM Stealer is a lightweight, modular malware strain built to interact directly with ATM hardware and vendor APIs. Its primary capabilities include:

  • Unauthorized cash dispensing (“jackpotting”)
  • Disabling network connections to avoid detection
  • Manual or remote command execution via USB or remote access
  • Stealth operation via service installation or fileless execution

While it lacks some advanced evasion techniques, Alice’s simplicity and direct targeting make it highly effective, especially in under-secured ATM environments.

Infrastructure Mapping Insight

Alice ATM Stealer Graph New

Through our infrastructure analysis, we have identified:

  • Command channels used for remote instructions and triggering ATM cashouts
  • Malware distribution points, often disguised as bank service utilities
  • Lateral movement patterns across financial networks
  • Indicators of reuse across multiple financial institutions and regions

Our infrastructure threat intelligence enables rapid identification of related assets, revealing the broader ecosystem supporting ATM-targeting malware and empowering clients to act early.

IOC Table – Block Immediately

Organizations should integrate the following hashes into their endpoint and network security systems to detect and block known malware variants associated with the Alice ATM Stealer campaign.

IOC TypeValue
SHA256B8063F1323A4AE8846163CC6E84A3B8A80463B25B9FF35D70A1C497509D48539
SHA25604F25013EB088D5E8A6E55BDB005C464123E6605897BD80AC245CE7CA12A7A70

Recommendations

To reduce exposure to ATM-targeted campaigns like Alice:

  • Monitor and restrict USB and physical access to ATM devices
  • Deploy endpoint protection with real-time execution prevention
  • Segment ATM networks from internal IT systems
  • Conduct regular audits of ATM software and firmware integrity
  • Use IOC-based hunting to identify signs of initial compromise

How We Help

  • Our Infrastructure Mapping Service provides:
  • Full threat actor infrastructure visualizations
  • IOC packages tailored for your environment
  • Intelligence-led threat hunting support
  • Early warning alerts for reused or mutated campaign infrastructure
  • Expert guidance on mitigation and response

We deliver actionable intelligence that enables your team to prevent financial loss, preserve trust, and stay ahead of financially motivated threat actors.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]