Malware That Spits Cash Out of ATMs Has Spread Across the World (vice.com) 47
A joint investigation between Motherboard and the German broadcaster Bayerischer Rundfunk (BR) has uncovered new details about a spate of so-called "jackpotting" attacks. From a report: A joint investigation between Motherboard and the German broadcaster Bayerischer Rundfunk (BR) has uncovered new details about a spate of so-called "jackpotting" attacks on ATMs in Germany in 2017 that saw thieves make off with more than a million Euros. Jackpotting is a technique where cybercriminals use malware or a piece of hardware to trick an ATM into ejecting all of its cash, no stolen credit card required. Hackers typically install the malware onto an ATM by physically opening a panel on the machine to reveal a USB port. In some cases, we have identified the specific bank and ATM manufacturer affected. Although a European non-profit said jackpotting attacks have decreased in the region in the first half of this year, multiple sources said the number of attacks in other parts of the world has gone up. Attacked regions include the U.S., Latin America, and Southeast Asia, and the issue impacts banks and ATM manufacturers across the financial industry. "The U.S. is quite popular," a source familiar with ATM attacks said. Motherboard and BR granted multiple sources, including law enforcement officials, anonymity to speak more candidly about sensitive hacking incidents.
So how does that work? (Score:5, Funny)
Re: (Score:2)
Asking for a friend...
$o you neEND _ MOre informatioN to rEpeat mY _ successFul Initiative foR $Tealing from ATMs?
Re:So how does that work? (Score:4, Funny)
All you have to do is tie a thick chain to the ATM, and to your truck. Pull the ATM out of the building, and smash it all to pieces. Now you have access to the USB port.
Re: (Score:3)
All you have to do is tie a thick chain to the ATM, and to your truck. Pull the ATM out of the building, and smash it all to pieces. Now you have access to the USB port.
Ok, done.
The ATM doesn't seem to have power anymore though...
... also what do I do with the unconscious security guard?
Re: (Score:3)
... also what do I do with the unconscious security guard?
Have you tried turning him off and back on again? Failing that, you could try, "Hey Siri..." or your co-defendent of choice.
Re: (Score:2)
Have you tried turning him off and back on again? Failing that, you could try, "Hey Siri..." or your co-defendent of choice.
Well, he was already turned off, so I tried to turning him on.
I can tell you, it did NOT have the desired effect!
Re:So how does that work? (Score:5, Funny)
All you have to do is tie a thick chain to the ATM, and to your truck. Pull the ATM out of the building, and smash it all to pieces. Now you have access to the USB port.
LOL.. I've seen this tried where the ATM was bolted to the floor. The would be crooks managed to trash the truck they had stolen when the ATM didn't come loose even after repeated attempts. Then once it let go, they didn't happen to have enough manpower to lift the thing into what was left of the truck so with flashing lights approaching in the distance they made a run for it, leaving the prize in the convenience store parking lot.
Re: (Score:3)
The best was a case in the UK where they used their own truck and the chain tore the rear bumper (with their tag) off. That and the security video made the cop's job pretty easy.
Re: (Score:2)
Those guys where amateurs. I have seen successful attacks with a Cat 966 loader and a dump truck although. The team made about 10 robberies, some getting caught on camera. I don't remember ever hearing that they caught them afterwards. They were smart enough to stop after a while and the loaders and trucks were stolen.
Re: (Score:2)
Colorado Springs Police Department detectives helped identify two people who were wanted in connection with a string of ATM thefts that happened around the turn of 2018. Thursday morning, detectives searched a Fremont County house with the assistance of the FBI and SWAT teams from Fremont and El Paso counties on a warrant for the thefts, and they also found two vehicles that were stolen from Colorado Springs plus narcotics and firearms. Police said two suspects were identified.
https://www.krdo.com/news/colo... [krdo.com]
Re: (Score:2)
Re: (Score:3)
Those would've been stupid thieves. Believe it or not, most of those (especially from Cat) use the exact same key. Which you can buy copies of on eBay.
It's mostly a practicality problem - a company may have dozens of loaders spread out among a few worksites. They are pretty much identical in every way, and thus key management is a pain. There's usually no license plate on them (since they operate on private property and are simply trucked in and ou
Re: (Score:2)
Well, that was easy! Or, at least, it was once I stole the backhoe and a dump trunk.
...Any tips on getting all this red stuff off the money, though? I tried putting it through the washing machine, but it hasn't helped at all.
Re: (Score:2)
Asking for a friend...
With an accomplice, inside job.
So, get friend with somebody designing ATMs and you are on your way.
usb is not behind locked and alarmed door? (Score:2)
usb is not behind locked and alarmed door?
and alarmed as in it and key pad like the ADT ones for the alarm.
Re: (Score:2)
Re: (Score:2)
usb is not behind locked and alarmed door?
and alarmed as in it and key pad like the ADT ones for the alarm.
Naw....probably as easy to hack as a Moto Terminator! https://www.youtube.com/watch?... [youtube.com]
Just pop off a panel and good to go!
Re: (Score:2)
usb is not behind locked and alarmed door? and alarmed as in it and key pad like the ADT ones for the alarm.
AND disabled? Come on, disable that USB port in software when there is money in the machine. How hard is that? Plenty of ways to stop this exploit.
Re: (Score:2)
Uhm, the USB port was most likely intended for updates to the software. Making the legit updater take all the money out is too much of a hassle.
Re: (Score:3)
Re:usb is not behind locked and alarmed door? (Score:5, Interesting)
Re: (Score:2)
Video is sadly boring (Score:2)
I really wanted to see a video with an ATM spitting out bills cartoon style, as they flew through the air and rained down all over the place.
Sadly the video is a guy hitting a key and getting a handful of cash, then repeating the same command after he takes that money out of the machine by hand... hardly a mad jackpot. More of a Rinse and Repeat attack if you ask me.
Re: (Score:2)
Uhm, that scene exists... look in the archives for "Hasbro Family Game Night" hosted by a young Todd Newton.
I can see it now (Score:5, Funny)
Scene: the engineering lab of an ATM manufacturer.
"I thought you said that bytecode was to flush the cash."
"Flush the cache, you absolute dumbfuck. The cache."
Diebold was talked quite a bit about in 2000 (Score:2)
Back in 2000, Diebold was known as an ATM maker who was dabbling in election voting machines... and boy did they have a mess to flush out. Too many donations to Republicans by the owners, and an attempt to copyright what eventually became open source.
Really, ATM software should be controlled by the card networks such as MasterCard and Visa. Whoever wrote the software involved in this kind of hack must have their priorities wrong.
Idiots. (Score:4, Interesting)
ATM machine running Windows, or any other full-blown PC operating system? That's an attack surface you'll never be able to secure. How about hiring proper embedded programmers for your embedded application? There are plenty of operating systems designed for this sort of purpose: Minimal footprint, highly modular. Maybe VxWorks?
Re: (Score:3)
Re:Idiots. (Score:5, Informative)
ATM machine running Windows, or any other full-blown PC operating system?
Of course, they are WindowsXP based.
The whole industry is full of security-illiterates, as was also proven by the "press shift 5 times" attack in 2017 [fossbytes.com]. But hey, those employees are cheaper than those who have a clue.
Re: (Score:2)
The whole industry is full of security-illiterates, as was also proven by the "press shift 5 times" attack in 2017 [fossbytes.com]. But hey, those employees are cheaper than those who have a clue.
Holy crap, what ATM needs a full keyboard?
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
You *can* hack WxWorks. But it'll be a lot harder. This is hacking with a minimal level of physical access - they are getting access to USB ports, not crowbaring open the cash box and hooking a car battery up to the motor wires.
Re: (Score:2)
Re: (Score:2)
They'd have USB slots, yes - but they'd only come with the drivers actually required for whatever purpose they had in mind. You couldn't just plug a USB HID into them and start entering keyboard and mouse commands, for one. You'd still need to cryptographic sign all updates, but it'd be significantly harder to get around that signing given USB access.
Dear Malware (Score:1)
What Would You Do... (Score:2)
Re: (Score:2)
...if you walked past an ATM and it started spitting out cash?
Look for the TV cameras because obviously SOMEBODY is trying to resurrect the 1960's "reality" show called "Candid Camera"
WHY, OH WHY!? (Score:2)
More efficient ways to get money (Score:1)
The slips of paper are valuable. But imagine if you could get the printer of those slips of paper to print some up just for you?
Just trading bonds for t-bills for cash overnight (Score:2, Informative)
Before the transaction:
The bank has $1 million in 30-day US government bonds
The Fed has $1 million in cash
After the transaction:
The bank has $1 million in cash
The Fed has $1 million in 30-day US government bonds
The bank has a million dollars before and after. The Fed has a million before and after. No money has been created. The bank just sold a bond that is almost equivalent to cash anyway. They buy it back in a day or two.
What it adds is liquidity - when you go to the ATM the bank can't give you savin
Re: (Score:3)
Re: (Score:2)
I thought of an ATM spitting dollar bills at a delighted thief, then I thought of what else spits dollars bills and I thought of the central bank. And the big news in the financial world is the seize-up of the repo market and the Feds current multi-billion dollar bailout of that market, which is again the Fed spitting money.
Circuitous and a little off-topic, I know. Anyway.
(nods smiling) That was me :) (Score:1)
Linking to motherboard? (Score:1)
Portfolio (Score:2)
Anybody with a Atari Portfolio can get easy money out of an ATM.