Tuesday, May 13, 2025
HomeComputer SecurityMalicious Hackers Steal Money From ATM by Connecting Laptop with ATM Cash...

Malicious Hackers Steal Money From ATM by Connecting Laptop with ATM Cash Dispenser

Published on

SIEM as a Service

Follow Us on Google News

The researchers discovered a dangerous black box attack tool called “KoffeyMaker” which is used by cybercriminals to steal money from ATM by connecting a laptop with the ATM machine cash dispenser.

An atm-based attack is discovered often around the world in the various form of operation by cybercriminals with sophisticated tools and they employing new tactics and techniques.

These incidents have been notified in European banks and they frequently reported in attacks since they were unclear how did this happen in their ATM.

- Advertisement - Google News

After the detailed investigation was done by Kaspersky security research team confirmed that they were dealing with a black box attack.

Black box attack refers that cybercriminals opened the ATM and connect their laptop with the cash dispenser and simply leave the device inside.

This crime scene indicates that the “crime instrument” to be a laptop with ATM dispenser drivers and a patched KDIAG tool.

Later attacker gains the remote access through USB GPRS modem and they are using windows OS with XP, ME, or 7.

Cash out from ATM moments

Once everything goes well then cybercriminals returned to the ATM and pretending to normal ATM users in order to run the KDIAG tool by accomplished a remote connection with the laptop.

Later they provide an instructions to the dispenser to issue the cashout form ATM machine and they will retrieve the laptop on a later moment.

               ATM dispenser connected to a computer without the necessary drivers
According to Kaspersky, The whole operation could well be done solo, but the scheme whereby a “mule” handles the cash and ATM side, while a second “jackpotter” provides technical support for a share of the loot, is more common. 

Hardware encryption between ATM PC and its dispenser will be the better solution to prevent such attack but if it fails single ATM can spit out tens of thousands of dollars.

This attack is very similar to the earlier ATM based attack Cutlet Maker used by this new tool and Kaspersky Lab products detect as RiskTool.Win32.DIAGK.a and same tools used for various bank robbers.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Microsoft Patch Tuesday May 2025 Released With the Fixes for 72 Flaws With 5 Actively Exploited 0-Day

Microsoft has released its May 2025 Patch Tuesday updates, addressing 72 security vulnerabilities across...

Ivanti Released Security Updates to Fix for the Mutiple RCE Vulnerabilities – Patch Now

Ivanti, a leading enterprise software provider, has released critical security updates addressing vulnerabilities across...

Fortinet FortiVoice Zero-day Vulnerability Actively Exploited in The Wild

A critical stack-based buffer overflow vulnerability (CWE-121) has been discovered in multiple Fortinet products,...

Ransomware Attacks Surge by 123% Amid Evolving Tactics and Strategies

The 2025 Third-Party Breach Report from Black Kite highlights a staggering 123% surge in...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

INDOHAXSEC Hacker Group Allegedly Breaches Malaysia’s National Tuberculosis Registry

The Indonesian hacker group "INDOHAXSEC" has allegedly breached the National Tuberculosis Registry (NTBR) of...

Is this Website Safe: How to Check Website Safety – 2025

is this website safe? In this digital world, Check a website is safe is...

Firefox 133.0 Released with Multiple Security Updates – What’s New!

Mozilla has officially launched Firefox 133.0, offering enhanced features, significant performance improvements, and critical...