Malware discovered on ATMs in Mexico has been improved and translated into English, suggesting it could be used elsewhere, according to security firm Symantec .
There are two versions of the Ploutus malware . Both, as we previously reported, are designed to empty ATMs.
Unlike most malware, Ploutus can be installed in a fairly old-fashioned way: with a bootable CD on an ATM system running Microsoft Windows. The installation method suggests that cybercriminals are targeting standalone ATMs where access is easier.
Ploutus displays a graphical user interface that allows the hacker to enter a numeric sequence into the ATM keypad, so the malware can be controlled from a keyboard, said Daniel Regalado, a malware analyst at Symantec.
Kevin Haley, director of Symantec Security Response, said in an interview earlier this month that the attackers have deep knowledge of the software and hardware used in ATMs.
Ploutus’ source code “contains Spanish function names and poor English grammar that indicate the malware was coded by Spanish-speaking programmers,” Regalado said.
In a new post, however, Regalado said Ploutus has been made much more powerful and translated into English, suggesting the same malware could be exploited in countries other than Mexico.
Symantec has already advised ATM programmers to change the boot order in the BIOS to allow only booting from the hard drive and not from CDs, DVDs or USB sticks. The BIOS , the security firm also says, should be password-protected.
Symantec published a video that shows the different ways the malware can be exploited.
See it

