What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The headline “New Ploutus ATM Malware Variant at Large” dates to SecurityWeek’s Jan. 12, 2017 report on Ploutus-D. That report described malware targeting Diebold ATMs and interacting with KAL’s Kalignite platform. It is a historical account, not evidence that the same variant or configuration is prevalent today. Separately, U.S. prosecutors described a Ploutus variant in a 2026 ATM-jackpotting case; those claims remain allegations, and the later case does not establish that it involved the exact Ploutus-D sample described in 2017.

What did the 2017 Ploutus-D report describe?

SecurityWeek’s Jan. 12, 2017 article relayed findings attributed to FireEye security researchers. It described Ploutus-D as malware that could interact with KAL’s Kalignite multivendor ATM platform and targeted Diebold machines. The article also reported KAL’s claim that Kalignite supported 40 ATM vendors in 80 countries at the time. Those figures are historical claims reported by SecurityWeek, not a current or independently verified count. Read SecurityWeek’s 2017 report.

The report said the malware could run on Windows 10, 8, 7, and XP, and described a Launcher component and obfuscation. It also said the attacker needed physical access to the ATM and a keyboard, and that an activation code featured in the cash-dispensing operation. These are high-level descriptions of the reported 2017 behavior, not a current operating procedure or evidence that every ATM running those systems was affected.

SecurityWeek relayed researchers’ assessment that Kalignite’s broad vendor support could make wider targeting technically possible with code changes. That was a statement about potential capability—not confirmation that all vendors supported by Kalignite had been compromised.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Implementing Security for ATM Networks
  • Used Book in Good Condition

What does the 2026 DOJ case say?

In a Jan. 26, 2026 announcement, the U.S. Department of Justice described allegations of a nationwide ATM-jackpotting conspiracy that developed and deployed a Ploutus variant. DOJ said the malware was intended to issue unauthorized commands to ATM cash-dispensing modules and was designed to delete evidence of its deployment. The announcement said an additional indictment brought the case’s then-reported total to 87 charged defendants. That is a date-specific count, not a current tally. DOJ’s account describes allegations in charging documents, not established guilt. Read DOJ’s Jan. 26, 2026 announcement.

On Oct. 2, 2026, DOJ reported that an alleged developer appeared in court in Nebraska and pleaded not guilty. The department also described alleged anti-analysis features and files intended to remove malware evidence. A not-guilty plea is not a finding of guilt, and these accusations remain subject to court proceedings. Read DOJ’s Oct. 2, 2026 update.

Rank #2
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
  • Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
  • Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
  • Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)

How are the 2017 report and 2026 case related?

Point of comparison 2017 report 2026 DOJ case updates
Source and date SecurityWeek, Jan. 12, 2017, relaying FireEye researchers’ findings. U.S. Department of Justice announcements dated Jan. 26 and Oct. 2, 2026.
Evidence described Reported technical capabilities and ATM platform/vendor context. Prosecutorial allegations and a later court-appearance update.
Specifics reported Ploutus-D, Diebold ATMs, and KAL’s Kalignite platform. An alleged Ploutus variant, unauthorized cash-dispensing commands, and evidence deletion.
What the source establishes What SecurityWeek reported about the 2017 variant; not present-day prevalence. What prosecutors allege in the case; not a finding that every allegation is true.

The reports share the Ploutus family name and ATM-jackpotting context, but the sources do not establish that the exact 2017 Ploutus-D sample or targeting configuration was used in the later conspiracy. They should be treated as separate reports unless court records or technical evidence establish a more specific connection.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should ATM operators take from these reports?

The reports show why physical access to ATMs and unauthorized dispenser commands are relevant security concerns, but they do not provide a current, authoritative mitigation checklist. Operators should obtain operational guidance from their ATM vendor, acquiring bank, and relevant law-enforcement or government cyber authorities. The 2017 account and 2026 DOJ releases are not substitutes for current, system-specific instructions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.