Feeds

Easily picked CD-ROM drive locks let Mexican banditos nick ATM cash

Who needs an inside man when you've got a boot disc?

SANS - Survey on application security programs

Lax security at Mexican banks has allowed cybercriminals to put their own malware-ridden CDs into ATM machines in order to gain control of the easily-compromised cash machines.

The Ploutus malware was installed after "criminals acquired access to the ATM’s CD-ROM drive and inserted a new boot CD into it". The ruse was possible because many ATMs in Mexico use a simple lock that is easily picked, allowing the attackers to gain physical access to the machines.

Attacks involving getting malware onto ATMs are rare but far from unprecedented. Normally all sorts of trickery is necessary before being able to get a trojan onto a target machine.

Malware-based ATM scams have previously involved using corrupt insiders to infect hole-in-the-wall machines. Learning how an ATM machine works by posing as an repair technician is also unnecessary thanks to Ploutus. You don't need a genius security researcher to develop a fiendishly cunning ATM attack, either.

Schoolboy errors made the self-service ATM-pwning tactic all too easy for Mexican crooks. The extent of the resulting scam - either in terms of how much money was lost or how many machines were infected - remains unclear. However details of how the malware itself works are fairly well understood.

Information security firm Trustwave has completed an analysis of the malware after obtaining samples of the malicious code. Infected machines still carry out their normal functions of dispensing cash. But if a particular key combination is input into the compromised device, the attacker will be presented with a hidden GUI, written in Spanish, complete with drop-down menus apparently designed for a touch screen.

Once crooks input a passcode - derived from a fixed four digit PIN combined with the figures for the date and month – they obtain the ability to dispense money from the compromised ATM.

"If you are a bank or the owner/operator of ATMs in Mexico, you will want to examine your machines for evidence of tampering," advises Josh Grunzweig, an ethical hacker in TrustWave's SpiderLabs team. "Banks and ATM owner/operators outside of Mexico could also benefit from an inspection of their ATMs."

"Examples of targeted malware like Ploutus serve as a reminder of the importance of a thorough security review of ATMs and the back-end systems connected to them," he added.

Grunzweig has put together a blog post explaining how the malware works - containing code snippets and a screenshot of the GUI cybercrooks are able to feast their eyes upon once the malware is installed on compromised cash machines - here.

This is ATM fraud without recourse to skimmers to harvest the card details of consumers or other more complex approaches. So far Ploutus-based attacks were targeted against ATMs at off-premise locations, according to self-service device information security software developer SafenSoft.

"The emergence of new malware with ability to directly extract cash from ATMs is a very alarming sign for self-service device security," Stanislav Shevchenko, chief technology officer at SafenSoft, warns. "Malware like this allows the cybercriminals to skip the whole process of cash withdrawal they have to take part in after using traditional ATM trojans and skimmer-like devices to steal the plastic card information.

"Additionally, by spreading malware like that criminals can easily bypass the traditional antivirus-based protection on the ATMs. If that trojan gets massively distributed any bank without specialised protection software on its ATMs will have hard times ahead," he added. ®

Combat fraud and increase customer satisfaction

More from The Register

next story
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
prev story

Whitepapers

Designing a defence for mobile apps
In this whitepaper learn the various considerations for defending mobile applications; from the mobile application architecture itself to the myriad testing technologies needed to properly assess mobile applications risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.