{
	"id": "3d1aa4aa-f232-4b50-a918-21b854abce6b",
	"created_at": "2026-04-06T00:09:56.2492Z",
	"updated_at": "2026-04-10T03:21:13.528792Z",
	"deleted_at": null,
	"sha1_hash": "8dc29e33c7059295911214a4f439ae8d1791e4d9",
	"title": "Threat Group Cards: A Threat Actor Encyclopedia",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 47199,
	"plain_text": "Threat Group Cards: A Threat Actor Encyclopedia\r\nArchived: 2026-04-05 21:07:34 UTC\r\nHome \u003e List all groups \u003e List all tools \u003e List all groups using tool GreenDispenser\r\n Tool: GreenDispenser\r\nNames GreenDispenser\r\nCategory Malware\r\nType ATM malware\r\nDescription\r\n(Proofpoint) GreenDispenser provides an attacker the ability to walk up to an infected\r\nATM and drain its cash vault. When installed, GreenDispenser may display an ‘out of\r\nservice’ message on the ATM -- but attackers who enter the correct pin codes can then\r\ndrain the ATM’s cash vault and erase GreenDispenser using a deep delete process, leaving\r\nlittle if any trace of how the ATM was robbed.\r\nInformation\r\n\u003chttps://www.proofpoint.com/us/threat-insight/post/Meet-GreenDispenser\u003e\r\n\u003chttps://documents.trendmicro.com/assets/white_papers/wp-cashing-in-on-atm-malware.pdf\u003e\r\nMalpedia \u003chttps://malpedia.caad.fkie.fraunhofer.de/details/win.green_dispenser\u003e\r\nAlienVault OTX \u003chttps://otx.alienvault.com/browse/pulses?q=tag:greendispenser\u003e\r\nLast change to this tool card: 27 December 2024\r\nDownload this tool card in JSON format\r\nAll groups using tool GreenDispenser\r\nChanged Name Country Observed\r\nUnknown groups\r\n  _[ Interesting malware not linked to an actor yet ]_  \r\n1 group listed (0 APT, 0 other, 1 unknown)\r\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=352b94fa-78c4-4133-b455-b7d81c079a7e\r\nPage 1 of 2\n\nSource: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=352b94fa-78c4-4133-b455-b7d81c079a7e\r\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=352b94fa-78c4-4133-b455-b7d81c079a7e\r\nPage 2 of 2\n\nUnknown groups _[ Interesting malware not linked to an actor yet ]_\n1 group listed (0 APT, 0 other, 1 unknown) \n   Page 1 of 2",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"ETDA"
	],
	"references": [
		"https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=352b94fa-78c4-4133-b455-b7d81c079a7e"
	],
	"report_names": [
		"listgroups.cgi?u=352b94fa-78c4-4133-b455-b7d81c079a7e"
	],
	"threat_actors": [],
	"ts_created_at": 1775434196,
	"ts_updated_at": 1775791273,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/8dc29e33c7059295911214a4f439ae8d1791e4d9.pdf",
		"text": "https://archive.orkl.eu/8dc29e33c7059295911214a4f439ae8d1791e4d9.txt",
		"img": "https://archive.orkl.eu/8dc29e33c7059295911214a4f439ae8d1791e4d9.jpg"
	}
}