Showing posts with label atm. Show all posts
Showing posts with label atm. Show all posts

Friday, October 27, 2017

Dark Web Site Selling ATM Malware

Wapack Labs observed ATM malware being sold on a dark web site. The malware targets all models of Wincore Nixdorf ATMs. The website explains that the Wincore 200xe ATMs are the easiest cash machines to exploit. The malware currently costs $1500.00 in Bitcoin for the first month (beginning 15 October 2017). After the first month, the ‘registration’ fee will be doubled. $1500.00 buys the buyer one credit, which is valid for a one time use on one ATM. To execute the attack users must log-in to their account on the website and receive a code (for one credit). The malware will then show the attacker the amount of cash in each money cassette that resides inside the ATM. The malware will then bypass the normal ATM system processes and the ATM will dispense all the bills in a desired cassette. The website also provides video links on their Tor site, demonstrating the method to fraudulently withdraw money, along with a free 10-page step-by-step Word document which explains how to use the malware. This guide describes in detail the tools required, software instructions, and details referencing different types of ATMs. This includes how the ATMs operate and how to find the interior USB ports...READ MORE

Wapack Labs has cataloged and reported on ATM malware in the past. An archive of related reporting can be found in the Red Sky Alliance portal.
  
WWW.WAPACKLABS.COM

Friday, March 17, 2017

ATM Access For Sale in Spanish Underground

An underground seller is marketing ATM maintenance manuals, access keys/codes, and private software for a major ATM manufacturer on an underground Spanish language forum. The seller claims to be an ATM mechanic, working in Mexico. This ATM information could compromise several, major Mexican banks. The ATM manufacturer has a presence in over 130 countries and provides hardware / software for banking and retail systems.

Wapack Labs has cataloged and reported on ATM hacking in the past. An archive of related reporting can be found in the Red Sky Alliance Portal.

WWW.WAPACKLABS.COM

Thursday, September 29, 2016

Credit Card Fraud & EMV Security Chip

Mobile banking fraud in Europe has increased by a factor of 20; a trend that could follow in the U.S.  Credit card fraud has hit critical mass in the U.S., causing a push in technology in new mobile apps, which could create a virtual playground for criminals.  A recent surge in the volume of U.S. credit card fraud has forced industries to adopt the European EuroPay, MasterCard and Visa (EMV) card system.  The resistance to the EMV conversion will result in higher merchant costs and ATM manufacturer resistance, which has prompted a growth in mobile banking apps.

Publication date:                        26 September 2016

Handling requirements:              Traffic light protocol (TLP) GREEN

Attribution/Threat Actors:          Unknown at this time

Actor Type:                                 Adversary capabilities have been assessed as Tier III*

Potential Targets:                        USA

Past Reporting:                            Red Sky Alliance: DOC-3952, DOC-4265

*Practitioners who focus on the discovery and use of unknown malicious code, are adept at installing user and kernel mode root kits10, frequently use data mining tools, target corporate executives and key users (government and industry) for the purpose of stealing personal and corporate data with the expressed purpose of selling the information to other criminal elements. 

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.