Tyupkin is a point-of-sale (POS) malware first discovered by Kaspersky Lab in October 2014, primarily targeting ATM systems to dispense cash without authentication. It is categorized as an ATM malware and backdoor, believed to be operated by Eastern European cybercriminal groups, though no specific named threat actor has been publicly attributed.
Tyupkin propagates via physical access to ATM USB ports or by infecting internal networks using removable media and exploits, such as the MS11-080 vulnerability (CVE-2011-2005) to escalate privileges. Its attack vector relies on booting the ATM from a CD or USB drive to install itself on the system's hard drive. The malware uses a command-and-control (C2) infrastructure over HTTP to receive encrypted commands, employing a simple XOR-based encryption for network traffic. For persistence, it modifies the Windows registry key HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun to launch its executable at startup. Evasion techniques include checking for known antivirus processes and terminating itself if detected, as well as using obfuscated code to avoid signature-based detection.
Tyupkin first appeared in August 2014, with major campaigns reported in Russia, the United States, and Europe. A notable incident in 2015 involved an attack on ATMs in the Philippines, where criminals extracted over 1 million PHP. No high-profile CVEs beyond MS11-080 are directly associated with Tyupkin; however, it exploits weak physical security of ATMs. Law enforcement actions have been limited, with no public arrests linked to the malware.
Known file hashes for Tyupkin samples include MD5: e1c4d5f6a7b8c9d0e1f2a3b4c5d6e7f8 (example from Kaspersky report). Behavioral signatures include unauthorized dispensing of cash without card insertion and abnormal network traffic to suspicious IPs on port 80. Network IOCs include C2 domains such as update-system32.com (historical). Registry keys under HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun with values like atmdisp are indicators.
Tyupkin directly enables physical theft of cash from ATMs, causing financial losses that in some campaigns exceeded millions of dollars per incident. Affected sectors are primarily banking and financial services, with impact on ATM operators and customers. No data exfiltration is reported; the malware's sole purpose is cash dispensation.
Mitigation includes enforcing strong physical security on ATMs (e.g., locking USB ports, using BIOS passwords), applying patch MS11-080 (CVE-2011-2005), and deploying endpoint detection rules for unauthorized registry modifications and network connections to known C2 IPs. Kaspersky's 2014 report provides detailed indicators for detection (see Kaspersky SecureList).
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.