Tuesday, February 27, 2024

ATMJackpot – New ATM Malware Steal Your Money From ATM using ATM Jackpotting Technique

New ATM Malware called ATMJackpot that is capable of dispensing large amounts of cash from the ATM Machine using ATM Jackpotting method.

Previously discovered ATM Jackptting Malware compromise the ATM by installing the malicious software and sophisticated hardware to pull out the cash.

Based on the Binary, researchers discovered this ATM malware originated from Hong Kong as 28th March 2018.

A few Months before sophisticated ATM skimming called “Shimmers”  targeted chip-based credit and Debit cards to steal your entire card information form POS(Point-of-sale) terminal.

Also, Attackers inject an another ATM Malware called Ploutus.D inject into the ATM machine and performing various Task

This newly Spreading ATM malware has a smaller footprint with a kind of small simple graphical user interface.

a simple graphical user interface

This Malware interface contains hostname along with the service provider information such as cash dispenser, PIN pad, and card reader information.

How Does This ATM Malware Works 

This ATM Malware propagates via physical access by an attacker using USB and also spreading via a network by downloading the malware on to already-compromised ATM machines.

Initially, windows class name called ‘WIN’ registered by the ATMJackpot malware that leads to handle all the malware activities.

According to netskope,  After registering a window class, the malware creates the window, populates the options on the window, and initiates the connection with the XFS manager

Later ATMJackpot malware starts it monitoring an operation of the events from different service providers and finally execute commands.

It using  3 Different commands to perform its malicious operation in the targeted ATM

1.Malware reads the data from PIN pad asynchronously using WFSAsyncExecute API

Read data from PIN Pad

2.Malware has the functionality to dispense cash

Dispense cash

3.Malware also has the functionality to eject the card

Eject ATM card

You can Also check the  Advanced ATM Penetration Testing Methods that help prevent the ATM Based Attacks.


Latest articles

ThreatHunter.ai Stops Hundreds of Attacks in 48 Hours: Fighting Ransomware and Nation-State Cyber Threats

The current large surge in cyber threats has left many organizations grappling for security...

WordPress Plugin Flaw Exposes 200,000+ Websites for Hacking

A critical security flaw has been identified in the Ultimate Member plugin for WordPress,...

Hackers Actively Hijacking ConnectWise ScreenConnect server

ConnectWise, a prominent software company, issued an urgent security bulletin on February 19, 2024,...

Heavily Obfuscated PIKABOT Evades EDR Protection

PIKABOT is a polymorphic malware that constantly modifies its code, making it hard to...

Anonymous Sudan Promoting New DDoS Botnet: Beware

It has come to light that a group known as Anonymous Sudan is actively...

Scattered Spider: Advanced Techniques for Launching High-Profile Attacks

Scattered Spider is a threat group responsible for attacking several organizations since May 2022...

8220 Hacker Group Attacking Linux & Windows Users to Mine Crypto

In a significant escalation of cyber threats, the 8220 Gang, a notorious Chinese-based hacker group, has intensified its attacks...
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Live Account Takeover Attack Simulation

Live Account Take Over Attack

Live Webinar on How do hackers bypass 2FA ,Detecting ATO attacks, A demo of credential stuffing, brute force and session jacking-based ATO attacks, Identifying attacks with behaviour-based analysis and Building custom protection for applications and APIs.

Related Articles