{
	"id": "c4444e0c-ce17-43f4-a356-bc663c5a5e55",
	"created_at": "2026-04-06T00:18:46.717513Z",
	"updated_at": "2026-04-10T03:21:14.376677Z",
	"deleted_at": null,
	"sha1_hash": "0b3eebdf1896ff3892ca23c3d060be36218de3fe",
	"title": "Threat Group Cards: A Threat Actor Encyclopedia",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 46478,
	"plain_text": "Threat Group Cards: A Threat Actor Encyclopedia\nArchived: 2026-04-05 21:50:55 UTC\nHome \u003e List all groups \u003e List all tools \u003e List all groups using tool ATMii\n Tool: ATMii\nNames ATMii\nCategory Malware\nType ATM malware, Backdoor\nDescription\n(Kaspersky) ATMii was first brought to our attention in April 2017, when a partner from\nthe financial industry shared some samples with us. The malware turned out to be fairly\nstraightforward, consisting of only two modules: an injector module (exe.exe,\n3fddbf20b41e335b6b1615536b8e1292) and the module to be injected (dll.dll,\ndc42ed8e1de55185c9240f33863a6aa4). To use this malware, criminals need direct access\nto the target ATM, either over the network or physically (e.g. over USB). ATMii, if it is\nsuccessful, allows criminals to dispense all the cash from the ATM.\nInformation Malpedia AlienVault OTX Last change to this tool card: 24 May 2020\nDownload this tool card in JSON format\nAll groups using tool ATMii\nChanged Name Country Observed\nUnknown groups\n _[ Interesting malware not linked to an actor yet ]_\n1 group listed (0 APT, 0 other, 1 unknown)\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6ece62e7-19f4-4568-953e-f240252f0568\nPage 1 of 2\n\nSource: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6ece62e7-19f4-4568-953e-f240252f0568\r\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6ece62e7-19f4-4568-953e-f240252f0568\r\nPage 2 of 2\n\nUnknown groups _[ Interesting malware not linked to an actor yet ]_\n1 group listed (0 APT, 0 other, 1 unknown) \n   Page 1 of 2",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"ETDA"
	],
	"references": [
		"https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6ece62e7-19f4-4568-953e-f240252f0568"
	],
	"report_names": [
		"listgroups.cgi?u=6ece62e7-19f4-4568-953e-f240252f0568"
	],
	"threat_actors": [],
	"ts_created_at": 1775434726,
	"ts_updated_at": 1775791274,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/0b3eebdf1896ff3892ca23c3d060be36218de3fe.pdf",
		"text": "https://archive.orkl.eu/0b3eebdf1896ff3892ca23c3d060be36218de3fe.txt",
		"img": "https://archive.orkl.eu/0b3eebdf1896ff3892ca23c3d060be36218de3fe.jpg"
	}
}