{"id":15139,"date":"2016-04-28T17:10:55","date_gmt":"2016-04-28T17:10:55","guid":{"rendered":"https:\/\/kasperskydaily.com\/b2b\/?p=5514"},"modified":"2020-04-10T15:36:29","modified_gmt":"2020-04-10T19:36:29","slug":"atms-attacks","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/atms-attacks\/15139\/","title":{"rendered":"Cash out with ease: why and how ATMs get attacked"},"content":{"rendered":"<p>Picture this: a late night, a badly lit corner in the slums; aside from a lonesome streetlamp, there\u2019s yet another dim light source \u2013 a lobby of a small sub-office of a major bank. It\u2019s too late for anyone to be around, street is empty, the surroundings have fallen asleep long ago.<\/p>\n<blockquote class=\"twitter-pullquote\"><p>Cash out with ease: why and how #ATMs get attacked<\/p><a href=\"https:\/\/twitter.com\/share?url=https%3A%2F%2Fkas.pr%2FPs3o&amp;text=Cash+out+with+ease%3A+why+and+how+%23ATMs+get+attacked\" class=\"btn btn-twhite\" data-lang=\"en\" data-count=\"0\" target=\"_blank\" rel=\"noopener nofollow\">Tweet<\/a><\/blockquote>\n<p>A shady figure emerges from the dark. It\u2019s next to impossible to tell the gender: the person is wearing a baggy street-style hoodie. The figure enters the lobby, comes to one of those cash dispensers, then freezes. A moment or two later, he (or maybe she? \u2013 you never know) starts packing something into a knapsack he has brought along. Once everything\u2019s done, the figure vanishes into the dark again\u2026<\/p>\n<p>\u2026In the morning the bank workers discover that at least one ATM is empty of cash.<\/p>\n<p>As readers could have already guessed, the hooded figure was a so-called money mule, the person hired for taking the cash from the compromised ATM \u2013 most likely the compromise had been performed remotely. \u00a0There\u2019s a reason this is a simple act to perform.<\/p>\n<p><strong>Easy come, easy go<\/strong><\/p>\n<p>In fact, modern ATMs are basically construction kits comprised of a number of hardware modules such as cash dispenser, a card reader, a keypad, the display (touch-sensitive or not), etc. But the main system unit is a very mundane PC; whatever custom software is installed there \u2013 ATM units management software, programs used to interact with the user, to communicate with the processing center, etc., all of it run on a quite common operating system.<\/p>\n<p>And the vast majority of today\u2019s ATMs still use Windows XP. For some reason certain banks also install Acrobat Reader 6.0, Radmin, TeamViewer and other unnecessary programs, and in some cases even dangerous software, making the device even more vulnerable.<\/p>\n<p>As we know, Microsoft finally <a href=\"https:\/\/business.kaspersky.com\/windows-xp-the-immortal-operating-system\/1621\/\" target=\"_blank\" rel=\"noopener nofollow\">dropped the support of this OS in 2014<\/a>. Two years onwards, it\u2019s still around in various forms. ATMs aren\u2019t exactly cheap devices, so it seems quite logical that as long as they can perform their functions, they are exploited, no matter what OS they are using.<\/p>\n<p>Microsoft dropped the support, so all newly discovered vulnerabilities are there to stay. And not just them: Securelist reports that many machines still have the unpatched critical vulnerability <a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms08-067.aspx\" target=\"_blank\" rel=\"noopener nofollow\">MS08-067<\/a> which allows remote code execution.<\/p>\n<p>In 2014, Kaspersky Lab researchers discovered <a href=\"https:\/\/securelist.com\/blog\/research\/66988\/tyupkin-manipulating-atm-machines-with-malware\/\" target=\"_blank\" rel=\"noopener\">Tyupkin<\/a> \u2013 one of the first widely known examples of malware for ATMs, and in 2015 company experts uncovered the <a href=\"https:\/\/business.kaspersky.com\/the-great-bank-robbery-carbanak-apt\/3598\/\" target=\"_blank\" rel=\"noopener nofollow\">Carbanak<\/a> gang, which, among other things, was capable of jackpotting ATMs through compromised banking infrastructure. Both examples of attack were possible due to the exploitation of several common weaknesses in ATM technology, and in the infrastructure that supports them. This is only the tip of the iceberg.<\/p>\n<p>Attackers sometimes use very sophisticated, multistage operations ending up with mass ATM compromise. The \u201cchain\u201d may indeed be long: some hacking group may compromise infrastructure of some telecom operator using a plain and simple social engineering technique. Having installed backdoors, the hacking group #1 may sell it to somebody else, who then discovers that the telecom company is serving some banks networks. Further research by hacking group #2 shows that ATMs are remotely accessible. Then hacking group #2 deploys some malware to redirect money to the rogue accounts or to force the cash out of certain ATMs at a certain time, which is picked by \u201chooded figures\u201d.<\/p>\n<blockquote class=\"twitter-pullquote\"><p>ATMs are much easier to #hack than meets the eye. Check out, why. #security<\/p><a href=\"https:\/\/twitter.com\/share?url=https%3A%2F%2Fkas.pr%2FPs3o&amp;text=ATMs+are+much+easier+to+%23hack+than+meets+the+eye.+Check+out%2C+why.+%23security\" class=\"btn btn-twhite\" data-lang=\"en\" data-count=\"0\" target=\"_blank\" rel=\"noopener nofollow\">Tweet<\/a><\/blockquote>\n<p>But it is quite possible that no exceedingly \u201chi-tech\u201d efforts are needed.\u00a0In many cases observed by Kaspersky Lab researchers, criminals don\u2019t even have to use malware to infect the ATM or the network of the bank it\u2019s attached to. Physical security for the ATMs themselves is a very common issue: often ATMs are constructed and installed in a way that means a third-party can easily gain access to the PC inside the ATM, or to the network cable connecting the machine to the Internet.<\/p>\n<p>And by gaining even partial physical access to the ATM, criminals potentially can install a specially programmed microcomputer (a so called black box) inside the ATM, which will give attackers remote access to the machine; or even reconnect the ATM to a rogue processing center.<\/p>\n<p>A fake processing center is a server that processes payment data and is identical to the bank\u2019s server despite the fact that it doesn\u2019t belong to the bank. Once the ATM is reconnected to a fake processing center, attackers can issue any command they want. And the ATM will obey.<\/p>\n<p><strong>XFS problem<\/strong><\/p>\n<p>Through research of commonly used ATMs (and actual attacks that have taken place recently) Kaspersky Lab researchers discovered that in the vast majority of cases the custom special software that allows the ATM\u2019s PC to interact with the banking infrastructure and hardware units, processing cash and credit cards, is based on XFS standard. This a rather old and insecure technology specification, originally created in order to standardize ATM software so that it can work on any equipment regardless of manufacturer.<\/p>\n<p>The problem is that XFS specification requires no authorization for the commands it processes; meaning that any app installed or launched on the ATM can issue commands to any other ATM hardware units, including the card reader and cash dispenser.<\/p>\n<p>Should malware successfully infect an ATM, it receives almost unlimited capabilities in terms of control over that ATM: it can turn the PIN pad and card reader into a \u201cnative\u201d skimmer or just give away all the money stored in the ATM upon a command from its hacker.<\/p>\n<p>XFS is clearly the major source of the problems with ATMs.<\/p>\n<p><strong>What to do then?<\/strong><\/p>\n<p>Kaspersky Lab experts say ATM manufacturers can reduce the risk of attack on cash machines by applying the following measures:<\/p>\n<p>\u2022 First, it is necessary to revise the XFS standard with an emphasis on safety, and introduce two-factor authentication between devices and legitimate software. This will help reduce the likelihood of unauthorized money withdrawals using trojans and attackers gaining direct control over ATM units.<br>\n\u2022 Secondly, it is necessary to implement \u201cauthenticated dispensing\u201d to exclude the possibility of attacks via fake processing centers.<br>\n\u2022 Third, it is necessary to implement cryptographic protection and integrity control over the data transmitted between all hardware units and the PCs inside ATMs.<\/p>\n<p>The large portion of the problem, however, is that while ATM manufacturers are developing more and more secure devices, banks themselves keep going on with obsolete Windows XP-based machines.<\/p>\n<p>\u201cThis is today\u2019s reality that causes banks and their customers huge financial losses. From our perspective this is the result of a longtime misbelief, that cybercriminals are only interested in cyberattacks against Internet banking. They are interested in these attacks, but also increasingly see the value in exploiting ATM vulnerabilities, because direct attacks against such devices significantly shortens their route to real money,\u201d \u2013 said Olga Kochetova, security expert at Kaspersky Lab\u2019s Penetration Testing department.<\/p>\n<p>For more details, check out the <a href=\"https:\/\/securelist.com\/analysis\/publications\/74533\/malware-and-non-malware-ways-for-atm-jackpotting-extended-cut\/\" target=\"_blank\" rel=\"noopener\">Securelist article<\/a> authored by Olga Kochetova, where today\u2019s issues with ATMs are described in detail.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Remember the beginning of Terminator 2: The Judgement Day where John Connor is shown hacking an ATM with an Atari Portfolio?<\/p>\n","protected":false},"author":209,"featured_media":15405,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1999,3052],"tags":[401,527],"class_list":{"0":"post-15139","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-business","8":"category-smb","9":"tag-atm","10":"tag-hacks"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/atms-attacks\/15139\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/atms-attacks\/3789\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/atms-attacks\/15139\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/atms-attacks\/15139\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/atm\/","name":"atm"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/15139","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/209"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=15139"}],"version-history":[{"count":7,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/15139\/revisions"}],"predecessor-version":[{"id":34840,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/15139\/revisions\/34840"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/15405"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=15139"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=15139"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=15139"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}