Tuesday, February 27, 2024

ATMDtrack – North Korean Hacker Group Attacking ATMs in India to Steal Card Details

The world’s most active Lazarus hacking group developed a new banking malware strain dubbed ATMDtrack targets India banks to steal financial data.

According to the Kaspersky report, the malware was designed to plant in ATMs, that could steal the data from the inserted card. The campaign has similarities with DarkSeoul campaign back in 2013 attributed to Lazarus group.

Lazarus Group most recent campaign is Operation Sharpshooter campaign which targets financial services, government, and critical infrastructure.

The North Korean state-sponsored Lazarus Group found active since 2007, the group involved in various high profile attacks including Sony and WannaCry ransomware attack.

ATMDtrack Malware Infection

When we first discovered ATMDtrack, we thought we were just looking at another ATM malware family, because we see new ATM malware families appearing on a regular base, said Kaspersky researcher, Konstantin Zykov.

In, the initial stage of the attack, threat actors drops the payload which is completely encrypted and an overlay of a PE file as an extra layer.

The malware dropper not only contains the executable that spies on the victim machine, but they also having a variety of payload executables following that is the main intention of spying on the victim.

  • Keylogging
  • Retrieve browser history
  • Gather host IP addresses, information about available networks and active connections,
  • List all running processes,
  • List all files on all available disk volumes.

The dropper also contains a RAT module, which gives attackers complete access to the system, they can perform various functions such as uploading/downloading, executing files, etc.

“ATMDTrack is a subset of the DTrack family, they naturally look different despite their similarities. ATMDtrack and Dtrack are the two new malware families added to Lazarus group’s arsenal,” Zykov wrote.

To perform the successful spying the internal network, an attacker looking for several security flaws such as weak network security policies, weak password policies, lack of traffic monitoring.

“So the organization needs to focus on tightening the network and password policies, use antivirus and regularly update it an keep on monitoring the network traffic,” Kaspersky warned.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Website

Latest articles

Abyss Locker Ransomware Attacks Microsoft Windows and Linux Users

FortiGuard Labs has released a report detailing the emergence and impact of the Abyss...

14-Year-Old CMS Editor Flaw Exploited to Hack Govt & Edu Sites

Hackers have exploited a vulnerability in a 14-year-old Content Management System (CMS) editor, FCKeditor,...

Zyxel Firewall Flaw Let Attackers Execute Remote Code

Four new vulnerabilities have been discovered in some of the Zyxel Firewall and access...

Hackers Abuse Telegram API To Exfiltrate User Information

Attackers have been using keywords like "remittance" and "receipts" to spread phishing scripts using...

ThreatHunter.ai Stops Hundreds of Attacks in 48 Hours: Fighting Ransomware and Nation-State Cyber Threats

The current large surge in cyber threats has left many organizations grappling for security...

WordPress Plugin Flaw Exposes 200,000+ Websites for Hacking

A critical security flaw has been identified in the Ultimate Member plugin for WordPress,...

Hackers Actively Hijacking ConnectWise ScreenConnect server

ConnectWise, a prominent software company, issued an urgent security bulletin on February 19, 2024,...
Guru baran
Guru baranhttps://gbhackers.com
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Live Account Takeover Attack Simulation

Live Account Take Over Attack

Live Webinar on How do hackers bypass 2FA ,Detecting ATO attacks, A demo of credential stuffing, brute force and session jacking-based ATO attacks, Identifying attacks with behaviour-based analysis and Building custom protection for applications and APIs.

Related Articles