Related Stories

  • Search for security
    With more than 30 000 web pages being infected every day, search engine results could increasingly lead to malware infection. Kari Larsen asks what the search engines are doing to mitigate security threats, and how users can protect themselves.
  • What’s in store for 2010?
    The Noughties are behind us now, but memories of a decade of data breaches will continue to haunt the infosec professional. If only there was a way of knowing what the threat landscape would look like in the months to come. Well you’re in luck as Davey Winder has dusted off the crystal ball and spoken to a broad church of infosec professionals to get some informed predictions for 2010
  • The black art of digital forensics
    What makes a good digital forensics specialist? Steve Gold looks at some of the latest applications and investigates how the forensic investigator’s role has evolved in order to comply with changing customer priorities
  • Information security and the recession
    As the recession continues to chew into budgets, and cyber criminals see increased opportunity for looting, CIOs must ensure that information security defences remain strong and affordable, even if this means a little bargaining. Stephen Pritchard looks at how organisations can negotiate the rough seas ahead.
  • US standards drive Canadian information security
    An absence of legislation and the presence of the laissez-faire attitude has resulted in Canada being rather lax when it comes to information security compliance. Robin Arnfield looks at how US standards are driving the Canadian information security marketplace

News

Russians hack Diebold ATM software

19 March 2009

The act of ATM Card skimming and shoulder surfing - used by criminals the world over to create cloned cards from users of bank cash machines - has entered a new dimension.

Instead of installing a `false front' card reader and monitoring users inputting their PINs via a video camera, Russian hackers have apparently started installing their own custom `sniffing' software on to the ATM's computer to get access to card plus PIN data.

According to newswire reports, a group of criminals managed to gain access to Diebold's Opteva ATMs - which are typically installed at chain stores to encourage frequent store visits - and hacked the programs driving the machines.

The Opteva ATMs are much more sophisticated than the ATM kiosks seen in pubs, clubs and 7-11 -style stores, Infosecurity notes. They offer chain stores a highly customisable, branded facility for customers to make deposits, print out statements and conduct many of the
transactions that normally require a bank branch visit.

They are also Microsoft Windows-driven.

Unconfirmed reports suggest that the criminals have rewritten the programme code for the ATMs to allow remote card and transaction `sniffing' access.

The criminals are then thought to have threatened or coerced site owners and/or staff to allow them out-of-hours access to the ATMs, and installed their own customised Windows software.

The sophisticated fraud has been countered by Diebold release a new set of software for the Opteva ATMs, which it is loading onto machines on a site-by-site basis.

Diebold reportedly learned of the incident back in January and sent out a global security update to its ATM customers using the Windows operating system.

Unsurprisingly, the firm is not releasing full details of what happened, including which businesses were affected, but has confirmed the criminal modus operandi as centering around the fraudsters gaining physical access to the machines to install their malicious program.

"Criminals gained physical access to the inside of the affected ATMs," Diebold says in its security update. "This criminal activity resulted in the operation of unauthorised software and devices on the ATMs, which was used to intercept sensitive information."

"The incident was a low-tech break-in to the ATM, but they had a high-tech knowledge of how to install the virus," says the company in a press statement.

Diebold has not said how the criminals were able to install the software on the systems, but its security update advises customers that there are several factors that can increase the risk of such a hack.

These precautions include using administrative passwords that may have been compromised; not using the locked-down version of Windows that Diebold provides; and misconfiguring the Symantec firewall software that comes with the ATMs.

Sophos claims that, after examining a copy of the hacked ATM code, that the program has been in `circulation' since last November.

Whoever wrote the malware, called Troj/Skimer-A by Sophos, probably had an insider's knowledge of the Diebold ATMs, says the IT security
vendor.

The software, says Sophos, uses quite a lot of functions that are not documented and replaces files in the Diebold folder, looks for printer plus screen data, as well as scanning for transactions in Ukrainian, Russian and US currencies.

http://www.diebold.com/solutions/atms/opteva/default.htm

 

This article is featured in:
Identity and Access Management Internet and Network Security IT Forensics

 

Comment on this article

You must be registered and logged in to leave a comment about this article.