AfterDawn: Tech news

VIDEO: Malware used to steal cash from ATM machines

Written by James Delahunty @ 09 Oct 2014 12:28 User comments (2)

VIDEO: Malware used to steal cash from ATM machines Kaspersky has detailed an interesting and naughty piece of malware that allowed attackers to steal cash directly from some ATM machines running an embedded Microsoft Windows OS.
The malware was active on at least 50 ATM machines in Eastern Europe, but there is some evidence that it has spread beyond the region to many other countries, including Canada, France, India and the United States. Kaspersky Lab's Global Research and Analysis Team came to this conclusion based on statistics of submissions made to the popular VirusTotal service.

It is targeted at ATM machines made by a major manufacturer, running a 32-bit embedded Windows operating system, and it is smart enough to hide itself using several tactics.

What is interesting is Kaspersky cited security camera footage at locations of infected ATM machines that show a bootable CD was used to infect them. It transfers the malware to the device, performs some checks and then edits the registry to boot the malware, which then interacts with ATM through the standard library MSXFS.dll. which Kaspersky informs readers is "Extension for Financial Services (XFS)."



It then runs in an infinite loop waiting for user input, but it will only accept commands by default on Sunday and Monday nights. It accepts multiple commands from an operator, who then must press the Enter button the keypad to proceed. Another clever trick is clearly intended at making it so only the right people can manipulate the machine, by requiring that a session key be entered.

It uses a random seed for every session which is displayed on screen, and the operator needs to know the algorithm to generate a session key based on this random seed. If all goes right, the operator can now do some things you wish you could do at an ATM, like entering a cassette number and having the ATM dispense 40 banknotes from it.

Check out a video demonstration.


Source: SecureList (Kaspersky)

Previous Next  

2 user comments

112.10.2014 16:43

and the banks that employ these machines deserve to be hacked, who's the dumb ass that thought it would be a great idea to give the user access to a bootable device.

if i found these machines i could probably scripts them to spit out everything they've got.

213.10.2014 05:51

sounds like something that is commonly seen in movies where someone runs a laptop to the atm and makes the atm spit out heaps of money.


Comments have been disabled for this article.

Latest news

VLC hits milestone: over 5 billion downloads VLC hits milestone: over 5 billion downloads (16 Mar 2024 4:31)
VLC Media Player, the versatile video-software powerhouse, has achieved a remarkable feat: it has been downloaded over 5 billion times.
1 user comment
Sideloading apps to Android gets easier, as Google settles its lawsuit Sideloading apps to Android gets easier, as Google settles its lawsuit (19 Dec 2023 11:09)
Google settled its lawsuit in September 2023, and one of the settlement terms was that the way applications are installed on Android from outside the Google Play Store must become simpler. In the future, installing APK files will be easier.
8 user comments
Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets (06 Jun 2023 9:19)
Roomba Combo j7+ is the very first Roomba model to combine robot vacuum with mopping features. And Roomba Combo j7+ does all that with a very clever trick, which tackles the problem with mopping and carpets. But is it any good? We found out.
Neato, the robot vacuum company, ends its operations Neato, the robot vacuum company, ends its operations (02 May 2023 3:38)
Neato Robotics has ceased its operations. American robot vacuum pioneer founded in 2005 has finally called it quits and company will cease its operations and sales. Only a skeleton crew will remain who will keep the servers running until 2028.
5 user comments
How to Send Messages to Yourself on WhatsApp How to Send Messages to Yourself on WhatsApp (20 Mar 2023 1:25)
The world's most popular messaging platform, Meta-owned WhatsApp has enabled sending messages to yourself. While at first, this might seem like an odd feature, it can be very useful in a lot of situations. ....
18 user comments

News archive