Share

Related Stories

  • Anti-virus: a technology update
    Anti-virus software might be the archetypal security product, but with so many high-profile malware attacks – including Stuxnet and Zeus – is it doing its job? Kevin Townsend investigates whether anti-virus software is still relevant
  • The Rise and Fall of Online Credit Fraud
    While Chip and Pin technology has certainly decreased in-store fraud, it has also re-directed criminals’ attention to online banks and shoppers. Stephen Pritchard investigates what methods cybercriminals are using to steal credit card data, and reports on how the finance sector is fighting back
  • Real-world ATM skimming techniques revealed
    Security researcher Brian Krebs has had a long-standing interest in the increasing problem of ATM skimmers - fraudsters who install hidden gadgets on cash machines with the intention of ripping off bank card customers. And he has posted an in-depth analysis of one such scam earlier today.
  • Digging Up the Hacking Underground
    The hacking underground is driven by three things: money, information, and reputation. Danny Bradbury takes a walk through its dark tunnels
  • Digging up the hacking underground
    The hacking underground is driven by three things: money, information, and reputation. Danny Bradbury takes a walk through its dark tunnels

Top 5 Stories

News

Russians hack Diebold ATM software

19 March 2009

The act of ATM Card skimming and shoulder surfing - used by criminals the world over to create cloned cards from users of bank cash machines - has entered a new dimension.

Instead of installing a `false front' card reader and monitoring users inputting their PINs via a video camera, Russian hackers have apparently started installing their own custom `sniffing' software on to the ATM's computer to get access to card plus PIN data.

According to newswire reports, a group of criminals managed to gain access to Diebold's Opteva ATMs - which are typically installed at chain stores to encourage frequent store visits - and hacked the programs driving the machines.

The Opteva ATMs are much more sophisticated than the ATM kiosks seen in pubs, clubs and 7-11 -style stores, Infosecurity notes. They offer chain stores a highly customisable, branded facility for customers to make deposits, print out statements and conduct many of the
transactions that normally require a bank branch visit.

They are also Microsoft Windows-driven.

Unconfirmed reports suggest that the criminals have rewritten the programme code for the ATMs to allow remote card and transaction `sniffing' access.

The criminals are then thought to have threatened or coerced site owners and/or staff to allow them out-of-hours access to the ATMs, and installed their own customised Windows software.

The sophisticated fraud has been countered by Diebold release a new set of software for the Opteva ATMs, which it is loading onto machines on a site-by-site basis.

Diebold reportedly learned of the incident back in January and sent out a global security update to its ATM customers using the Windows operating system.

Unsurprisingly, the firm is not releasing full details of what happened, including which businesses were affected, but has confirmed the criminal modus operandi as centering around the fraudsters gaining physical access to the machines to install their malicious program.

"Criminals gained physical access to the inside of the affected ATMs," Diebold says in its security update. "This criminal activity resulted in the operation of unauthorised software and devices on the ATMs, which was used to intercept sensitive information."

"The incident was a low-tech break-in to the ATM, but they had a high-tech knowledge of how to install the virus," says the company in a press statement.

Diebold has not said how the criminals were able to install the software on the systems, but its security update advises customers that there are several factors that can increase the risk of such a hack.

These precautions include using administrative passwords that may have been compromised; not using the locked-down version of Windows that Diebold provides; and misconfiguring the Symantec firewall software that comes with the ATMs.

Sophos claims that, after examining a copy of the hacked ATM code, that the program has been in `circulation' since last November.

Whoever wrote the malware, called Troj/Skimer-A by Sophos, probably had an insider's knowledge of the Diebold ATMs, says the IT security
vendor.

The software, says Sophos, uses quite a lot of functions that are not documented and replaces files in the Diebold folder, looks for printer plus screen data, as well as scanning for transactions in Ukrainian, Russian and US currencies.

http://www.diebold.com/solutions/atms/opteva/default.htm

This article is featured in:
Identity and Access Management  • Internet and Network Security • IT Forensics

 

Comment on this article

You must be registered and logged in to leave a comment about this article.