Exposing Alice ATM Stealer: Infrastructure Mapping of a Financial Threat
Financial institutions remain top targets for cybercriminal groups focused on high-reward operations.

Financial institutions remain top targets for cybercriminal groups focused on high-reward operations. One such malware family, Alice ATM Stealer, is designed specifically to compromise ATM systems, allowing attackers to dispense cash, bypassing legitimate banking processes.
Our security analysts have mapped the infrastructure behind a recent campaign involving Alice ATM Stealer, uncovering how cybercriminals structure, distribute, and manage these attacks. This mapping enables us to detect and disrupt malicious operations before they impact your organization.
Threat Overview
Alice ATM Stealer is a lightweight, modular malware strain built to interact directly with ATM hardware and vendor APIs. Its primary capabilities include:
- Unauthorized cash dispensing (“jackpotting”)
- Disabling network connections to avoid detection
- Manual or remote command execution via USB or remote access
- Stealth operation via service installation or fileless execution
While it lacks some advanced evasion techniques, Alice’s simplicity and direct targeting make it highly effective, especially in under-secured ATM environments.
Infrastructure Mapping Insight

Through our infrastructure analysis, we have identified:
- Command channels used for remote instructions and triggering ATM cashouts
- Malware distribution points, often disguised as bank service utilities
- Lateral movement patterns across financial networks
- Indicators of reuse across multiple financial institutions and regions
Our infrastructure threat intelligence enables rapid identification of related assets, revealing the broader ecosystem supporting ATM-targeting malware and empowering clients to act early.
IOC Table – Block Immediately
Organizations should integrate the following hashes into their endpoint and network security systems to detect and block known malware variants associated with the Alice ATM Stealer campaign.
| IOC Type | Value |
|---|---|
| SHA256 | B8063F1323A4AE8846163CC6E84A3B8A80463B25B9FF35D70A1C497509D48539 |
| SHA256 | 04F25013EB088D5E8A6E55BDB005C464123E6605897BD80AC245CE7CA12A7A70 |
Recommendations
To reduce exposure to ATM-targeted campaigns like Alice:
- Monitor and restrict USB and physical access to ATM devices
- Deploy endpoint protection with real-time execution prevention
- Segment ATM networks from internal IT systems
- Conduct regular audits of ATM software and firmware integrity
- Use IOC-based hunting to identify signs of initial compromise
How We Help
- Our Infrastructure Mapping Service provides:
- Full threat actor infrastructure visualizations
- IOC packages tailored for your environment
- Intelligence-led threat hunting support
- Early warning alerts for reused or mutated campaign infrastructure
- Expert guidance on mitigation and response
We deliver actionable intelligence that enables your team to prevent financial loss, preserve trust, and stay ahead of financially motivated threat actors.



