Infected ATMs Give Away Millions of Dollars Without Credit Cards 83
An anonymous reader writes: Kaspersky Lab performed a forensic investigation into cybercriminal attacks targeting multiple ATMs around the world. During the course of this investigation, researchers discovered the Tyupkin malware used to infect ATMs and allow attackers to remove money via direct manipulation, stealing millions of dollars. The criminals work in two stages. First, they gain physical access to the ATMs and insert a bootable CD to install the Tyupkin malware. After they reboot the system, the infected ATM is now under their control and the malware runs in an infinite loop waiting for a command. To make the scam harder to spot, the Tyupkin malware only accepts commands at specific times on Sunday and Monday nights. During those hours, the attackers are able to steal money from the infected machine.
This doesn't add up (Score:5, Interesting)
If you have access to the ATM physically, why not just take the cash there and then?
Re:This doesn't add up (Score:5, Informative)
If you have access to the ATM physically, why not just take the cash there and then?
Because there would only be a finite amount of cash in the machine. By installing this software, you can steal a little bit at a time, and the cash would be reloaded periodically.
Re:This doesn't add up (Score:5, Informative)
It's also easier to tie cash loss to an event where a bad actor had special physical access. I'd be willing to bet the cash box itself has monitors/procedors/audit trails to prevent theft/tampering from people who normally service it.
The trojan bypasses all that, hiding cash loss in an event that does not require special physical access (Normal walk-up transactions carried out by customers) The trojan also cleans up all the auditing logs so you less sure about when the loss occurred.
If, say, the bad actor is a crooked service man the gang of crooks can bribe him to slip their CD in and install the trojan. That way the cash gets taken when he's nowhere near the machine, and he has nothing to do with taking the cash all together. Or if, say, you're picking locks and breaking in to the machine to slip in your CD there's nothing suspicious (like an empty cash box) to point to the time where you could have broken in to the machine. You put the risk of the actual cash theft (Taking money from trojan compromised machines) on low rent thugs and suckers in your gang.
Re: (Score:1)
Re: (Score:3)
a) The programmer(s) working for the bank
b) The people servicing the ATM's
Unless of course the ATM's in questi
Re: (Score:2)
Re: (Score:2)
Re:This doesn't add up (Score:5, Insightful)
Going back repeatedly isn't going to work -- the bank or financial company maintaining the ATMs does actually count the money going into the machines and the amounts legally withdrawn and if they don't balance then investigations are carried out. Put in 10000 quatloos, 7000 quatloos withdrawn by customers over a few days, 1000 quatloos left when the next refill is carried out = something fishy. Cookie jar accountancy rules apply, eventually Mom will notice the distinct lack of cookies and eventually catch you cookie-crumb-handed.
Re: (Score:2)
Re:This doesn't add up (Score:4, Insightful)
yeah. those are called "atm fee's". Oh wait, we're talking about different criminals.
Re: (Score:2)
the problem you see, is ATMs require windows XP software. yes windows XP. http://www.theverge.com/2014/1/20/5326772/windows-xp-powers-95-percent-of-atms-worldwide [theverge.com]
So the malware simply connects to a botnet, hops through inadequate satellite networks makes a map and reinfects itself after the system is cleaned. i have seen windows xp machines infected by satellite communications they are after all devices that must obey 'this device must accept any interference received' which is usually a kill switch to make
Re: (Score:2)
How you can insert a bootable CD into ATM without having physical access to it? I havent seen any USB ports on the front nor CD drive slot...
Re: (Score:3)
You can have a locked box inside a locked box. Just because they can easily get into the outer layer doesn't mean they can easily get into the inner layer.
Re:This doesn't add up (Score:5, Interesting)
Re: (Score:1)
Because the money is physically protected and will get sprayed with paint if you try to physically remove them.
Re: (Score:2)
Re: (Score:2)
If you have access to the ATM physically, why not just take the cash there and then?
Because there would be a high level of accountability. If you have physical access, and were the guy working on the machine the night before money was missing, you'd be busted. This way, I can be the guy that works on the machine, and you can be the guy that steals all of the money. We meet up and half the cash.
At least this is how I assume it works.
Re:This doesn't add up (Score:5, Informative)
Not as easy as you think. A guy who used to live in the apartments across from me was a retired burglar. Found god in prison, went straight, yada yada. One of his old tricks was burglaring ATM machines. Apparently his trick was he'd tie a chain to the ATM and the other side to stolen truck and take off down the road with the ATM in tow. He'd then get out with a few men and lift the ATM into the truck and make a run for it.
It would take them about 4-5 days to extract the money. Apparently the cash reserves are booby-trapped so that tampering with the mechanism would destroy the cash. As a result removing the money was a complicated procedure involving slow dismantling and a lot of welding.
After his third attempt at it, they got a newer one, that was battery backed and had some sort of radio thing in it. Cops tracked it and they where done.
Re: (Score:2)
also unless you have
1 the cutters needed to rip the vault from the atm
2 a sizable truck
Good luck getting the cash out before even Barney Fife could walk up load The Bullet and arrest you.
Re: (Score:2)
Sounds like they would bleed them instead of emptying them. Their are limits to the amount you can withdraw at once. A couple machines a couple times a week would have a single guy living pretty well in a work free existence.
Re:This doesn't add up (Score:4, Informative)
Because it's easier to get to the electronics than the cashbox.
Inside these little ATMs is a steel box. Get that steel box open and you have full access to the electronics. But to get to the cash requires opening said box, then opening the safe holding the cash, which is vastly more protected.
The cash is dispensed from within the safe and exits out a slot in the safe (basically the safe carries a number of cash cassettes and the electronics count out the cash, which is why if they mis-load the cassettes, you can be short changed or given more than you expect.
Oh yeah, and the safe has all sorts of safeguards to destroy the cassettes should they be tampered with, making it even harder to get the cash out.
Of course, they assumed the electronics were secure, so the other way to get the cash out is via the front door. Bypasses all the safe security systems and everythign else.
Re: (Score:2)
I suppose you could trigger the dispenser to start dishing out cash nonstop, but it is not as easy as it sounds. Getting at the cash cassettes is not easy, either, because the lower half of an ATM is, as you might expect when thinking about it, built as a slightly modified safe. Getting at the computer and modifying the software really is the path of least resistance.
Source: I used to work on these machines.
Re: (Score:2)
You've never seen Barber Shop [youtube.com], have you?
Tie it to the camera (Score:1)
When the ATM is rebooting, would be a good time to mark the camera footage as in need of review.
Re: (Score:3)
These ATMs are probably the kind you find in smaller stores - about the size of a internet kiosk at a hotel - they're not made to be all-weather unsupervised secure, just "secure inside a store with an employee around."
These on XP? (Score:3)
I remember back when XP was officially discontinued there was some article that said something like 70% of ATM machines worldwide still ran XP. Anyone able to confirm if this is the case? If so, are they exploiting some vulnerability in XP that is never-to-be-patched?
Re:These on XP? (Score:4, Interesting)
Many, yes.
Some kiosk versions of XP are still getting patched.
Re: (Score:2)
Most ATMs I have ever seen are Windows, no idea what version. ... ... they don't need it, and software updates are usually distributed by bank internal networks, not by technicians running around with a CD.
But it is clearly to diagnose on the blue screen they show so often.
I guess many of them are NT and not even XP
What is bejond me is: why do they even have a CD drive
Re: (Score:2)
...and software updates are usually distributed by bank internal networks
I'm not sure I like the idea of rogue ATMs on the internal bank network.
Re: (Score:2)
Those networks are for ATMs only, rofl.
Banks are bad in many regards, but their I?t usually works fine, old fashioned perhaps but nevertheless up to the tasks.
Re:These on XP? (Score:5, Insightful)
If so, are they exploiting some vulnerability in XP that is never-to-be-patched?
They are exploiting a vulnerability that is found in almost every operating system, and which has yet to be patched by any vendor. It's called "running a program". As the summary says:
Re:These on XP? (Score:4, Informative)
That isn't an operating system flaw but a hardware flaw: loads data from device into memory and points the CPU at it.
What is actually surprising is that they don't use some kind of DRM-esque bootloader (much like you find in many phones) where it only boots an image with a matching signature.
Re: (Score:2)
They won't do anything that might increase their costs, as long as they can blame the owner for failing to secure physical access to the machine.
Re: (Score:3)
True. There's also, "Physical access means no security."
not Dollars, just banknotes (Score:2)
So many ways this could've been prevented? (Score:2, Insightful)
Why does an ATM have a cd drive, let alone usb ports or anything else? Why does it boot off of media without altering the BIOS and requiring a password? Why isn't the OS encrypted making modification require more difficult techniques like bootkits which has other protection mechanisms?
Re: (Score:3)
Cost, ease of deployment, maintenance and updates.
Re: (Score:1)
Can't they just update it via the internet?
(Note to ATM vendors: no, stop, that was a joke, do NOT... what? You already did? And you used which OS? No, please...)
It's nothing a few more fees can't cover (no text) (Score:2)
Re: (Score:2)
Re: (Score:3)
Speed. In the old days, telephone lines were EXTREMELY slow and they wanted to limit that to just the actual transaction details. Also, they would only call a modem when that transaction actually happened.
But you're right, for modern operations, they should just be dumb terminals.
Re:"Without attracting attention" (Score:4, Informative)
The bank is disconnected from the ATM during this process. Money isn't being removed from an account. Bills are being removed from a mechanical hopper, because the software on the kiosk has a service mode, accessible outside of normal service because the real software on the ATM has been replaced by a modified version that allows it without the normal controls.
Re: (Score:1)
Instead, they used dumb programmers with little or no intelligence. It was cheaper that way.
Can we stop using Cyber (Score:3)
these weren't cybercriminals, just criminals. They physically broke open ATM machines.
Re: (Score:3)
Except the criminals are Cybermen.
Re: (Score:2)
Probably covered by ATM fees. :(
So long as they aren't stealing from regular folks (Score:1)
So long as they aren't accessing working people's bank accounts, I'm surprisingly okay with this and hope they don't get caught. It's not like the banks wouldn't find some other excuse to raise my service charges. Or just plain seize my accounts during times of crisis.
So, go bank robbers!
Though...
Not sure I'd want to risk being destroyed over a bunch of funny money.
Being a bank robber seems like just another flavor of servitude. You're agreeing to value their make-believe money system by risking
This is small potatoes. (Score:5, Funny)
If you want to steal BIG, you have to own the bank - just ask those guys on Wall Street.
Seems to be an inside job. (Score:1)
The stupidity of an overspec device (Score:3)
Credit Cards? (Score:1)
smart (Score:2)