Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 21:50:55 UTC Home > List all groups > List all tools > List all groups using tool ATMii Tool: ATMii Names ATMii Category Malware Type ATM malware, Backdoor Description (Kaspersky) ATMii was first brought to our attention in April 2017, when a partner from the financial industry shared some samples with us. The malware turned out to be fairly straightforward, consisting of only two modules: an injector module (exe.exe, 3fddbf20b41e335b6b1615536b8e1292) and the module to be injected (dll.dll, dc42ed8e1de55185c9240f33863a6aa4). To use this malware, criminals need direct access to the target ATM, either over the network or physically (e.g. over USB). ATMii, if it is successful, allows criminals to dispense all the cash from the ATM. Information Malpedia AlienVault OTX Last change to this tool card: 24 May 2020 Download this tool card in JSON format All groups using tool ATMii Changed Name Country Observed Unknown groups _[ Interesting malware not linked to an actor yet ]_ 1 group listed (0 APT, 0 other, 1 unknown) https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6ece62e7-19f4-4568-953e-f240252f0568 Page 1 of 2 Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6ece62e7-19f4-4568-953e-f240252f0568 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6ece62e7-19f4-4568-953e-f240252f0568 Page 2 of 2 Unknown groups _[ Interesting malware not linked to an actor yet ]_ 1 group listed (0 APT, 0 other, 1 unknown) Page 1 of 2