New ATMJackpot Malware To Steal Your Money From ATMs Machine

atm_hack

New Malware called ATM Jackpot that is capable of dispensing large amounts of cash from the ATM Machine using ATM Jack potting method.Previously discovered ATM Jack potting compromise the ATM by installing the malicious software and sophisticated hardware to pull out the cash.

Based on the Binary, researchers discovered this ATM malware originated from Hong Kong as 28th March 2018.A few Months before sophisticated ATM skimming called “Shimmers” targeted chip-based credit and Debit cards to steal your entire card information form POS(Point-of-sale) terminal. Also, Attackers inject an another ATM Malware called Ploutus.D inject into the ATM machine and performing various Task.

This newly Spreading ATM  has a smaller footprint with a kind of small simple graphical user interface.This interface contains host name along with the service provider information such as cash dispenser, PIN pad, and card reader information.

How ATMJackpot Malware Works?

  1. The ATMJackpot  first registers the windows class name ‘WIN’ with a window procedure that is responsible for all of the activity.
  2. After registering a window class, it creates the window, populates the options on the window, and initiates the connection with the XFS manager.
  3. After initiating a connection with the XFS manager, the malware opens the session with the service providers and registers to monitor the events. opens a session with CDM (cash dispenser), IDC (card reader) and PIN (pin pad) service providers.

After successful registration, It can monitor the events from different service providers and execute the commands.

Commands:

  • It reads the data from PIN pad asynchronously using WFSAsyncExecute API call.
  • It has the functionality to dispense cash.
  • It also has the functionality to eject the card.

The ATMJackpotting technique are on rise in cyber crime activities. All banks should be concerned about ATM’s security. There are many ATM machine runs on Windows XP Operating system which is responsible to hack by cyber criminals easily. Microsoft had end the support for Windows XP in 2014.

courtesy: https://bit.ly/2H4QxVB

Facebook: https://www.facebook.com/aywenzit/
WordPress: https://aywenz.wordpress.com
Blogger: https://aywenz.blogspot.in/

 

Leave a comment