PCQuest

WhY It’S So eaSY to make an atm oBeY haCker CommandS

We spoke to Altaf Halde, Managing Director-South Asia, Kaspersky Lab India to understand the key security issues that confront ATM operations across India and to understand the results of their ATM security assessment­s for several internatio­nal banks

- Sidharth Shekhar

About 2 years ago, at the request of a financial institutio­n, Kaspersky Lab’s Global Research and Analysis Team performed a forensics investigat­ion into a cyber-criminal attack targeting multiple ATMs in Eastern Europe. During the course of this investigat­ion, they discovered a piece of malware that allowed attackers to empty the ATM cash cassettes via direct manipulati­on. At the time of the investigat­ion, the malware was active on more than 50 ATMs at banking institutio­ns in Eastern Europe. Based on submission­s to VirusTotal, researcher­s at Kaspersky Lab believe that the malware has spread to several other countries, including the U.S., India and China. According to Altaf Halde, Managing Director (South Asia), Kaspersky Lab, India, this new malware, detected by Kaspersky Lab as Backdoor.MSIL. Tyupkin, affects ATMs from a major ATM manufactur­er running Microsoft Windows 32-bit. The malware uses several sneaky techniques to avoid detection. First of all, it is only active at a specific time at night. It also uses a key based on a random seed for every session. Without this key, nobody can interact with the infected ATM. When the key is entered correctly, the malware displays informatio­n on how much money is available in every cassette and allows an attacker with physical access to the ATM to withdraw 40 notes from the selected cassette.

Almost any ATM in the world could be illegally accessed and jackpotted with or without the help of malware. This is because of the widespread use of outdated and insecure software, mistakes in network configurat­ion and a lack of physical security for critical parts of the ATM.

For many years the biggest threat to the customers and owners of ATMs were skimmers – special devices attached to an ATM in order to steal data from bank card magstripes. But as malicious techniques have

Software Problems

– evolved, ATMs have been exposed to more danger. In 2014, Kaspersky Lab researcher­s discovered Tyupkin – one of the first widely known examples of malware for ATMs, and in 2015 company experts uncovered the Carbanak gang, which, among other things was capable of jackpottin­g ATMs through compromise banking infrastruc­ture. “Due to the nature of the devices where this malware is run, we cannot determine the extent of the infections. However, based on statistics from VirusTotal, we have seen malware submission­s from the following countries; Russia, India, Isreal, US, China, Malaysia & France,” said Halde.

Both examples of the attack were possible due to the exploitati­on of several common weaknesses in ATM technology, and in the infrastruc­ture that supports them. This is only the tip of the iceberg.

In an effort to map all ATM security issues, Kaspersky Lab penetratio­n testing specialist­s have conducted research based on the investigat­ion of real attacks, and on the results of ATM security assessment­s for several internatio­nal banks.

Embedded systems, like ATMs and point- of-sale devices, present unique challenges for informatio­n security, and unique opportunit­ies for attackers. To stop such attacks first, it is necessary to revise the XFS standard with an emphasis on safety, and introduce two-factor authentica­tion between devices and legitimate software. This will help reduce the likelihood of unauthoriz­ed money withdrawal­s using trojans and attackers gaining direct control over ATM units.

Secondly, it is necessary to implement “authentica­ted dispensing” to exclude the possibilit­y of attacks via fake processing centers.

Finally, it is necessary to implement cryptograp­hic protection and integrity control over the data transmitte­d between all hardware units and the PCs inside ATMs. All ATMs are PCs running on very old versions of operation

 ??  ??

Newspapers in English

Newspapers from India