Windows XP ATM's Under Hacker Attacks in Europe - US Could Be Next!

June 4, 2009 by John Messina ATM Machine

(PhysOrg.com) -- There have been approximately 20 ATM's in Eastern Europe that have been compromised. These attacks are in the early stages of development and would probably gain momentum and even spread to US ATM machines.

A security outfit, TrustWave's SpiderLabs performed the analysis of malware found installed on compromised ATMs in the Eastern European region. The ATM's that were compromised ran Microsoft Windows XP. The malware captures magnetic stripe data and PIN codes from the private memory space of transaction-processing applications installed on infected ATM.

The attacker can gain full control of the infected ATM through a customized user interface built into the malware. This is accomplished by inserting a controller card into the ATM's reader.

TrustWave's analyses don't believe the malware has networking functionality that would send data to other, remote locations over the Internet. The malware would output the harvested data through the ATM's receipt printer or write the data to a storage device inserted into the ATM's .

TrustWave stated; "this malware is unlike any we have ever had experience with. It allows the attacker to gain complete control over the ATM to obtain track data, Pins and cash from each infected machine."

"We believe the current attack vector is an early version of the malware sample, and future attacks will add functionality such as propagation via the ATM network. If an attacker can gain access to one machine, the malware will evolve and propagate automatically to other systems."

A dropper file named isadmin.exe, is installed into the ATM and executed within the C:\WINDOWS directory of the compromised machine. The malware then proceeds to control the Protected Storage service that would handle the original lsass.exe executable file, located in the C:\WINDOWS\system32 directory, to point to the infected file.

The malware is designed to remain active in the event the ATM crashes and has to restart.

© 2009 PhysOrg.com


   
Rate this story - 3.6 /5 (15 votes)

Rank Filter

Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

  • Bob_Kob - Jun 04, 2009
    • Rank: 3.7 / 5 (3)
    upgrade to windows 7 lol
  • moj85 - Jun 04, 2009
    • Rank: 5 / 5 (3)
    time to use not windows for important financial transactions.
  • frajo - Jun 04, 2009
    • Rank: 3.7 / 5 (3)
    time to use not windows for important financial transactions.


    In former times, ATMs used to run OS/2. They never got hacked.
  • moj85 - Jun 04, 2009
    • Rank: 4.5 / 5 (2)
    oh please, they never got hacked my ass. of course they did. XP just is probably easier to hack. haha
  • CouchP - Jun 04, 2009
    • Rank: 4 / 5 (1)
    Why do these vendors provide writable card readers, and operator card access without having a physical mechanical key? Shouldn't you be required to gain physical access into the machine internals prior to accessing? Anyone can explain this?
  • gishpupp - Jun 04, 2009
    • Rank: 5 / 5 (3)
    Ahahahahaha, too funny. Who got the payoff to sell WinXP for ATM's. lol This is the dumbest, most laughable situation I've heard all year.

    Is this the same group that leaves US military desktops connected to the internet without firewalls and then tells the world "We're under attack!"?
  • LuckyBrandon - Jun 04, 2009
    • Rank: 1 / 5 (2)
    actually this is something can EASILY be dealt with using a software restriction policy, which is built into Windows XP....with the best method being to define the hashed algorithm most likely I think.
    It really shows that whatever this banks IT security policy is for ATM systems is SEVERELY lacking.
    Different banks will have different security.
    In my thinking here, an ATM machine doesnt contact another ATM machine from another bank to get approval to take out cash (they connect back to their systems at the main bank datacenter who then will check against another bank if necessary and then reply back to the ATM on whether or not to spit out the funds), therefore, fundamentally, the trojan cannot spread via those means. This is most likely why the code does not include a replication mechanism, and possibly never will. The developers will have to figure out how to propagate into the banks actual backend network in order to do that, and from there, they can infect only that banks ATMs (but, the whole network of them). From there they also have a better potential of intruding another banks networks, again, depending on the other banks security.

    The media is just trying to make this "scareware" to have a bunch of bs stories to tell about technologies they dont understand whatsoever.
  • docatomic - Jun 04, 2009
    • Rank: not rated yet
    I don't know about the bank machines, but the stand-alone 'white label' ATM machines these days are running Windows CE, not XP. Furthermore, older pre-Windows models don't run any operating system at all; they are loaded instead with dedicated proprietary firmware that is launched from a ROM bootstrap routine at startup, and that firmware is not x86-based code. Older machines are inherently more secure for that reason, as well as the fact that they communicate through dialup modems instead of directly through the Internet.

    Although the new Windows-based technology was implemented primarily to allow ATM firms to gain additional revenue through on-screen advertisments, it may also pose some interesting 'unforeseen' possibilities and consequences.

    Suppose, for instance, an ATM firm wished to encroach upon the territories of a competitor. An employee of the firm could simply pose as a customer attempting to use one of the competitor's machines, while in reality employing a card for the purpose that had been cleverly re-programmed in such a manner as to inject a malware. The advent of the proposed new 'chip-and-pin' card readers could possibly make this even easier, as the chip on the card must be accessed by the machine directly.

    The malware injected would not even have to be purposed towards skimming. All that would really be required would be a partial shutdown or corruption of the targeted machine; anything that would further erode the site owner's confidence in the competitor firm's ability to provide effective service and reliable machine operation. The sales representative of the attacking firm could then approach the victimised client with a "better deal" offer, and so gain that site's transaction revenues.

    I think I'll stick with the older machines, thanks. They cost less to service, anyway.
  • Expiorer - Jun 05, 2009
    • Rank: 5 / 5 (2)
    That's why they stole some ATMs.
    They investigated them and found that ATMs can be compromised with specially designed card - exploit.
  • EvgenijM - Jun 05, 2009
    • Rank: 5 / 5 (2)
    Well, they got what they deserved for trusting M$.
  • david_42 - Jun 07, 2009
    • Rank: not rated yet
    Since the use of MS is driven by the 'need' to display ads, one must ask a question: Has anyone on the planet ever paid any attention to an ad on an ATM?
  • docknowledge - Jun 07, 2009
    • Rank: not rated yet
    The Chinese know how to deal with this. Stop pandering to the marketing dichotomy between Windows and Linux. Develop special purpose chips, with custom operating systems, that don't allow common hacking techniques.

    No, it isn't that frigging difficult. It's just that it doesn't fit in Microsoft's plan for world domination.
  • docatomic - Jun 08, 2009
    • Rank: not rated yet
    Since the use of MS is driven by the 'need' to display ads, one must ask a question: Has anyone on the planet ever paid any attention to an ad on an ATM?





    What matters most is not whether anyone pays any attention to full-motion advertisements displayed on ATM machines, but rathermore the fact that ATM firms are now able to garner additional revenue by selling that extra service.
  • lengould100 - Jun 11, 2009
    • Rank: not rated yet
    Only kiddie-hackers care what OS is on the target machine. Real hackers work in machine language.

June 4, 2009 all stories

Comments: 14

3.6 /5 (15 votes)

  • hide
  • Related Stories

  • Hacking Citibank's Virtual Keyboard
    created May 12, 2007 | popularity not rated yet | comments 0
  • The Raging Windows Worm has attacked over 8.9 Million Computers
    created Jan 19, 2009 | popularity not rated yet | comments 0
  • Conficker Worm Prepares For A New Release On April 1
    created Mar 27, 2009 | popularity not rated yet | comments 0
  • Microsoft reminds users about Feb. 3 virus
    created Feb 01, 2006 | popularity not rated yet | comments 0
  • 2007 looks like year of 'malware'
    created Sep 18, 2007 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • how to welding thin SS foil (0.002")?
    created Feb 08, 2010
  • Civil Engineering is hazardous to your career prospects
    created Feb 06, 2010
  • hot water circulator, kitchen faucet, ? mixing
    created Feb 06, 2010
  • Static or dynamic pressures in duct
    created Feb 06, 2010
  • More from Physics Forums - General Engineering

Other News

A general view of the arrival area of the Whistler Creek Alpine Skiing venue

Google Maps climbs to Olympic peaks

Technology / Internet

created 2 hours ago | popularity not rated yet | comments 0

Google sent snowmobiles rigged with cameras into Canadian mountains so folks snug and warm at home will get views of slopes at the Winter Olympic Games kicking off on Friday.


The power of 'random'

The power of 'random': 'Seemingly loopy' technique could dramatically improve communications networks

Technology / Computer Sciences

created 11 hours ago | popularity 4.8 / 5 (6) | comments 5 | with audio podcast

A radical new approach to the design of communications networks, called "network coding," promises to make Internet file sharing faster, streaming video more reliable, and cell-phone reception better -- among ...


Warner CEO sees e-book 'fracas' as helping music

Technology / Business

created 3 hours ago | popularity not rated yet | comments 0

(AP) -- The head of Warner Music Group expressed hope on Tuesday that the recent "fracas" over the price of e-books would help give content creators such as his company more pricing power over device makers.


'Revolutionary' water treatment units on their way to Afghanistan

Technology / Engineering

created 5 hours ago | popularity 5 / 5 (3) | comments 1 | with audio podcast

The United States Army has taken delivery of the first two units of a "revolutionary" waste-water treatment system that will clean putrid water within 24 hours and leave no toxic by-products, according to scientists at Sam ...


Imec and Holst Centre achieve breakthrough in battery-less radios

Imec achieves breakthrough in battery-less radios

Technology / Semiconductors

created 6 hours ago | popularity 5 / 5 (5) | comments 0 | with audio podcast

At today's International Solid State Circuit Conference, Imec and Holst Centre report a 2.4GHz/915MHz wake-up receiver which consumes only 51µW power. This record low power achievement opens the door to battery-less ...