
In the fall of 2016, one of the banks turned to the “Kaspersky Laboratory”, which discovered an empty ATM with a small hole with a diameter of a few centimeters near the keyboard for entering the PIN code. The hole was covered with a sticker. Later, researchers found about a dozen more similar thefts of ATMs of the same model.
Experts began to study this model and found a port connected to the computer bus - a subsystem through which its components exchange data with each other. In particular, through the tire there was access to the dispenser to issue money. Through the drilled hole, the hollow easily reached the port.
Employees of the Laboratory for five weeks studied signals transmitted by the tire, and as a result were able to deal with the data transfer protocol. It turned out that the teams are transmitted in a weakly protected form inside the ATM.
After that, the researchers have collected a simple ATMeGA microcontroller device (these are used in Arduino boards), batteries, several capacitors and adapter for connecting to the port. The device, which cost $ 15, made it possible to transfer the team to the dispenser to issue money.
One of the crackers who used this vulnerability caught the police - when it happened, is not specified. He did not have a device based on a microcontroller - instead, he used a laptop with a cable, with which he connected through the hole to the port of the ATM and gave the command to give all the money.
When using this method, a small problem arose: at some point, the computer inside the ATM understood that the dispenser was working without his command, and rebooted. But after rebooting, the attacker could again send the team to issue money - and do so until the ATM does not issue all the bills.
The method with drilling a hole allowed you to get money without noise - if the attacker decides to open the lock and remove the entire front panel, the alarm will react.
The Kaspersky Laboratory did not specify which banks or models of ATMs were vulnerable to such a hacking method, but noted that such an attack was already used more than once in Russia and Europe. It is quite difficult to protect against it: manufacturers cannot simply update the software, they need to replace the equipment inside ATMs. In extreme cases, you can limit access to ATMs or set video surveillance near them.
***
Also on April 3, the Kaspersky Lab said about another way to steal money from ATMs - it is called a non -fiber attack. The bottom line is to infect corporate networks of banks with the virus, and already through them, using remote administration, transfer commands to ATMs. At least one Russian bank suffered from it.
Since the attack occurs remotely, everything looks innocent from the side - the attacker does not even touch the ATM. Just from time to time, the car gives packs of 40 bills that remains to be taken. It takes less than 20 minutes to clean one ATM, after which you can move to the next point.
A non -fiber attack is called because it leaves no traces: after issuing the money, the virus removes itself. But at one of the affected ATMs, researchers managed to find two text documents in which the journals of operations were stored (they, apparently, did not leave by mistake).
There were several phrases in English in these magazines: “I am entering the process of issuing”, “I will unlock the dispenser” and “Catch money, bitch!” Presumably, these lines were displayed on the ATM screen at the moment when the attacker came to pick up the money.
Researchers looked for these lines in the texts of other viruses and found the right one - it was previously discovered in Russia and Kazakhstan. According to Kaspersky Laboratory, the virus that was called Atmitch can be launched on the vast majority of ATMs. With the help of non -fire attacks, more than 800 thousand dollars have already been stolen.
Sultan Suleimanov