On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

March 18th, 2009

Diebold ATMs infected with credit card skimming malware

Posted by Dancho Danchev @ 9:40 am

Categories: Anti Virus, Complex Attacks, Data theft, Malware, Rootkits

Tags: Security, ATM, Diebold, Insider, Credit Card Fraud, Skimming, Dancho Danchev

Theory comes into practice. Yesterday, Sophos Principal Virus Research Vanja Svacjer posted an analysis of Troj/Skimer-A, a malware affecting Windows-based Diebold cash machines and capable of intercepting credit card details and their associated PINs.

The malware is exclusively coded to target Russian, Ukranian and American currency transactions, with isolated incidents confirmed by Diebold in January, 2009. What’s particularly interesting about the ATM-based malware, is that it requires an insider access to the machine compared to the mainstream external attack in the form of using an ATM skimming device.

Here are more details on how the malware operates:

“The main executable is a dropper with the drop object stored in one of the PE resources, as often is the case with Trojan droppers. The code stops and modifies the Protected storage service to launch the dropped file lsass.exe from the Windows folder, not the original one in Windows System folder and attempts to replace some files belonging to the software used by ATMs.

The main Trojan executable contains the code to handle the magnetic card reader using undocumented Diebold Agilis 91x functions, inject code to ATM’s processes, parse transactions in Ukrainian, Russian and US currencies and use printer, probably for printing the stolen data. I am also fairly sure that some of the instructions to the keyboard for typing PIN numbers are connected with hooks to log the captured PINs.”

Given the potential of infiltrating the assembly line and shipping the machines malware pre-infected, next to tampering with public machines through social engineering,  ATM based malware isn’t going mainstream just yet. How come? Better “alternatives” from a scammer’s perspective.

In October, 2008, Zero Day provided an exclusive overview of what may easily be the future of ATM skimming (External ATM skimmers with built-in SMS notification for secure extraction of stolen data) which ultimately solves two of the ATM skimmer’s biggest problems - securely recovering the obtained data without the risk of getting caught when coming back to obtain the device, and the lack of trust between the scammers orchestrating the attack and the involved insiders who can potentially scam them — according to Sophos, Troj/Skimer-A is capable of encrypting the intercepted financial data, a practice aimed to ensure that the insiders that infected the ATM machine wouldn’t scam the rest of the people participating.

Capable of sending 1,856 SMS messages, namely 1,856 transactions without recharging, this $8,500 device empowers scammers with both, anonymity and flexibility allowing them to build an infrastructure of tampered ATMs across the globe. Of course, their approach isn’t perfect since financial institutions across the globe are considering adapting to the threat by jamming cell phone communications around ATM machines. Last month, South Korea’s National Police Agency indicated a similar intention following Japan’s ban on cell phones around ATMs.

Whether the insider access prerequisite drives scammers away from the malware infecting approach, external ATM skimming attacks are definitely here to stay.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 34 Talkback(s)
RE: Diebold ATMs infected with credit card skimming malware
Great article. Malicious malware is present in the society. That's why credit card companies are doing their best to avoid fraudulent activities.
CreditCard ... (Read the rest)
Posted by: credit card Posted on: 09/03/09 You are currently: a Guest | | Terms of Use
thtas why i only use bank atms with my card and CC for everything else  Been_Done_Before | 03/18/09
More reasons why Windows has no place period  itguy08 | 03/18/09
You are such a fanboy  croberts | 03/18/09
RE: You are such a fanperson  n0neXn0ne | 03/18/09
Would you be so kind as to provide evidence to sustain your claims?  InAction Man | 03/18/09
Perhaps if you read the article...  NStalnecker | 03/18/09
Using unsubstantiated claims to avoid seeing reality for what it is  InAction Man | 03/18/09
Here is a challenge for you:  NStalnecker | 03/19/09
Give us a Break  paullkellysr | 03/19/09
Blaming the OS?  LandonAB | 03/18/09
RE: Blaming the OS ... is legit  n0neXn0ne | 03/18/09
Thanks  LandonAB | 03/18/09
Noooo!!! Blame the user  InAction Man | 03/18/09
RE: Noooo!!! Blame the user ... for what ?...  n0neXn0ne | 03/18/09
Simple - easy to hack  itguy08 | 03/19/09
An ATM Running Windows!  Grayson Peddie | 03/18/09
RE: Diebold ATMs infected with credit card skimming malware  gertruded | 03/19/09
Wow what a hater. You sound like one of those "Bush planned 9-11"  invmgr@... | 03/24/09
RE: Diebold ATMs infected with credit card skimming malware  madcrutch | 03/19/09
And these guys are the same ones  rcfoulk@... | 03/19/09
The OS isn't the problem ...  Tony R. | 03/23/09
RE: Diebold ATMs infected with credit card skimming malware  PatrynXX | 03/19/09
RE: Diebold ATMs infected with credit card skimming malware  cb77305 | 03/19/09
Really???  i8thecat | 03/19/09
That's no guarantee, unfortunately.  TripleII | 03/19/09
REALLY?????  for8 | 03/20/09
Isn't Diebold the company that makes voting machines?  Tony R. | 03/23/09
Diebold's voting machines  brambeus | 03/25/09
MD5's for known good files?  madrucke@... | 03/23/09
cheaper losses  zorfor | 03/23/09
Cheaper?  dabble53 | 03/23/09
Agreed  ExCorpGuy | 03/24/09
They steal votes and money - Dibold sucks!!  Reality Bites | 04/15/09
RE: Diebold ATMs infected with credit card skimming malware  credit card | 09/03/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads