When is a storage service not a storage service?
By Elinor Mills
Published: 5 June 2009 16:20 GMT
Malicious software has been found on Eastern European ATMs that allows criminals to steal account data and PINs and even empty the machine of its cash, a computer forensics expert said.
About 20 cash machines have been compromised in that manner, mostly in Russia and the Ukraine, but there are "early indications" of compromised ATMs in the US, said Nicholas Percoco of Trustwave, which provides data security and payment-card compliance services.
Percoco, who heads up Trustwave's SpiderLabs, the forensics team that discovered the malware on the ATMs, said he could not elaborate further on where the compromised ATMs were located and how they were used.
Someone had to manually install the malware on the machines, so it is likely that an insider is responsible - either an employee at the bank, the ATM vendor, a company that services the machines or someone close to an insider, Percoco said.
A-Z of security
The machines, all running Windows XP, had an executable programme on them that was masquerading as a legitimate Windows protected storage service, he said. The malware looks at all the data being processed by the ATM. It records the account information that is stored on the magnetic stripes on cards inserted into the machine and the encrypted PIN blocks that are generated when someone types in their number, Percoco said.
Although the PINs are encrypted, criminals could potentially intercept the encryption keys exchanged with the bank and use them to decrypt the PINs, he added.
Once the malware has been hidden on the ATM for a period of time, the criminal can return to the machine and use a special "trigger" card to control the ATM. The criminal can print out the stolen data directly from the machine, or instruct the machine to dispense all the cash it has, according to Percoco. Bank cash machines can hold as much as $600,000 at a time, he said.
"There is evidence that [trigger] cards were used," he said, adding that he could not comment on the number of accounts affected or amount of money stolen. The malware was first installed on at least one of the machines in July 2007, he said.
This is not the first time that malware has been discovered on ATMs, Percoco said. "But this is probably the most sophisticated malware found on an ATM," he said. "In all the versions we've looked at [the criminals] are enhancing the application as they go. They must be getting feature requests from someone."
The latest version of the malware code found on some of the machines includes a function for writing the stolen data onto a card with a memory chip on it, which are commonly used in Europe, he said. However, that function does not appear to work, he added.
Although the malware was installed on the ATMs manually, it is possible that future attacks would involve the propagation of the malware through the ATM network, he said.
A spokeswoman for Trustwave told silicon.com sister site ZDNet UK that none of the compromised ATMs conformed to the Payment Card Industry Data Security Standard (PCI-DSS).
"These are non PCI-compliant ATMs, they don't have proper security in place, and they are not running antivirus," she said.
While the ATMs are not internet facing, Genser added that Trustwave has evidence the malware is being spread elsewhere. "We believe this is a test bed, and will probably propagate," the spokeswoman added.
ZDNet UK's Tom Espiner contributed to this story.
Original article: Hacked ATMs let criminals steal cash, PINs from CNET News.com
"The machines, all running Windows XP, had an exec...
Harry Rogers
XP? Any OS at all that was not designed especiall...
Joe Whitehead
This means challenging all exceptions to their policy to ensure business justification and complianceWe require several Enterprise and Solution ...
Administrator - Payment Card Industry (PCI) Administrator required for market leading high street retail company for an initial 3 month contract. The ...
s largest global ATM networks, offering cash access in local currency in over 170 countries. s Account Information Security Programme, which promotes ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Tim Ferguson
On a new Voyager, tackling fraud and the intellectual challenge
Interview: Nationwide IT director, Peter Stafford
Nick Heath
David Lister on smart grids and why he left RBS
Interview: National Grid CIO
Andy Jones
Why banks will push ahead with offshoring
Comment: Even if they don't want to
Catherine Stagg-Macey
Legacy IT holding back insurers
Comment: Economic crisis means finance giants must step lively
Julian Goldsmith
The City fund manager with no IT department
Q&A: How asset management is embracing the cloud...
Peter Cochrane
Peter Cochrane's Blog: How tech can solve the banking crisis
Bring on a machine-based economy