The headline “New Ploutus ATM Malware Variant at Large” referred to a report published on Jan. 12, 2017: SecurityWeek relayed FireEye researchers’ findings about Ploutus-D, which they said targeted Diebold ATMs and interacted with KAL’s Kalignite platform. That historical report is distinct from a later case: in 2026, the U.S. Department of Justice described allegations involving a Ploutus variant in an ATM jackpotting conspiracy. The shared family name does not establish that the same sample or ATM configuration was involved.
What the 2017 headline referred to
SecurityWeek’s Jan. 12, 2017 report described Ploutus-D, a variant that FireEye researchers said could interact with KAL’s Kalignite multivendor ATM platform and targeted Diebold machines. The report characterized Kalignite as supporting 40 ATM vendors in 80 countries, attributing those figures to KAL. They describe the platform’s reported footprint at that time, not a current or independently verified market count. SecurityWeek’s report
According to that account, the malware had a Launcher component, used obfuscation, and could run on Windows 10, 8, 7, and XP. The reported cash-dispensing operation involved physical access to an ATM, a connected keyboard, and an activation code. These are historical descriptions attributed to FireEye research, not a current operational guide or an assessment of how prevalent the variant is today.
SecurityWeek relayed the researchers’ assessment that support for multiple ATM vendors could make broader targeting technically possible with code changes. That was a statement about potential, not confirmation that every vendor supported by Kalignite had been compromised.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
What DOJ reported in 2026
The later developments are a separate criminal case, not evidence that the exact Ploutus-D sample described in 2017 remained active or was used in the same way. DOJ’s Jan. 26, 2026 announcement said an additional indictment brought the case’s then-reported total to 87 charged defendants. Prosecutors alleged a nationwide conspiracy developed and deployed a Ploutus variant to issue unauthorized commands to ATM cash-dispensing modules and designed it to delete evidence of deployment. Those statements describe allegations in charging documents, not findings of guilt. DOJ’s Jan. 26 announcement
On Oct. 2, 2026, DOJ reported that an alleged developer appeared in Nebraska court and pleaded not guilty. DOJ also described anti-analysis features and files intended to remove evidence of malware. The reported court appearance and plea are procedural facts; the defendant’s alleged role and the underlying accusations remain unproven. DOJ’s Oct. 2 update
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
How the two accounts differ
| Question | 2017 Ploutus-D report | 2026 DOJ case reporting |
|---|---|---|
| Date and source | SecurityWeek, Jan. 12, 2017, relaying FireEye researchers’ findings. Source | U.S. Department of Justice announcements dated Jan. 26 and Oct. 2, 2026. Jan. 26 source; Oct. 2 source |
| Evidence described | Reported technical findings about a named variant, platform, and ATM vendor. | Prosecutors’ allegations and updates about charges and a court appearance. |
| Specificity | Named Diebold ATM and Kalignite platform context. | Alleged deployment of a Ploutus variant in a nationwide ATM jackpotting conspiracy. |
| What it establishes | What researchers reportedly observed about Ploutus-D in 2017; not present-day prevalence or confirmed compromise of every Kalignite-supported vendor. | What DOJ alleged and reported procedurally in 2026; not guilt, nor proof that the exact 2017 sample or configuration was used. |
What ATM operators and customers should take from the reports
The reports concern malicious software and ATM crime, not a consumer product or a demonstrated change to ordinary ATM use. They do not provide a current, official mitigation checklist for ATM operators. Operators should seek current, system-specific direction from their ATM vendor, acquiring bank, and relevant law-enforcement or government cyber authorities rather than treating a historical attack description as an operational security standard.
For customers, a cash-dispensing crime allegation does not by itself establish that a particular ATM or account has been affected. If a withdrawal appears on an account that the customer did not make, contact the bank promptly through its official channel and follow its dispute process. The cited reports do not specify a customer notification or compensation policy.
Quick Recap
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
Rank #4
Rank #3
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




