HomeinetKaspersky Lab experts discover ATM vulnerabilities

Kaspersky Lab experts discover ATM vulnerabilities

According to research by Kaspersky Lab specialists, any criminal in the world could gain illegal access and profit from an ATM, with or without the help of malicious software. This occurs due to the widespread use of outdated and insecure software, network configuration errors, and lack of physical security for the critical parts of the ATM.Kaspersky Lab

For many years, the biggest threat to ATM customers and owners has been so-called skimmers, i.e. special devices that are attached to an ATM to steal data from the magnetic strips of cards. But as malicious techniques have evolved, ATMs have been exposed to greater risks. In 2014, Kaspersky Lab researchers discovered Tyupkin, one of the first widely known examples of ATM malware. In 2015, the company’s experts uncovered the Carbanak, which, among other things, could profit from ATMs by breaching banking infrastructure. Both attacks were carried out because criminals managed to exploit several common weaknesses in ATM technology and the infrastructure that supports them. And that’s just the tip of the iceberg.

In an effort to map all ATM security issues, Kaspersky Lab's penetration testing experts have conducted research, based on the investigation of real attacks, as well as the results of ATM security assessments for several international banks.

The research by Kaspersky Lab specialists concludes that malware attacks can be carried out against ATMs due to numerous security issues. Initially, all ATMs are computers that run very old operating system versions, such as Windows XP. This makes them vulnerable to «infections» from malicious programs and attacks via exploits. In the overwhelming majority of cases, the specialized software that allows the ATM computer to interact with banking infrastructure and hardware units, for processing cash and credit card transactions, is based on the XFS standard.

It is a rather old and fragile technological specification, which was originally created to standardize ATM software so that it can operate on any equipment, regardless of the manufacturer. Once the malicious software «infects» successfully an ATM, it gains almost unlimited control capabilities over the machine. For example, it can turn the PIN keypad and the card reader of the ATM into a «physical» skimmer or simply hand over all the money stored in the ATM, upon the hacker's command.

In many cases studied by Kaspersky Lab, criminals do not need to use malware to “infect” the ATM or the bank network it is connected to. This is due to the lack of physical security for the ATMs themselves – a very common problem for these devices. Very often, ATMs are built and positioned in a way that means third parties can easily gain access to the computer inside the ATM or the network cable that connects the machine to the Internet. By gaining even partial physical access to the ATM, criminals can potentially:

  • Install a specially programmed microcomputer (the so‑called black box) inside the ATM, which will give attackers remote access to the ATM.
  • Reconnect the ATM to a fake «processing center».

The fake «processing centre» is software that processes payment data and is identical to the bank's software, even though it does not belong to the bank. Once the ATM connects to a fake processing centre, attackers can issue any command they wish. And the ATM will simply execute it.

The connection between the ATM and the processing center can be protected in various ways. For example, it can use hardware or software VPN, SSL/TLS encryption, firewall or MAC authentication, which are applied to the xDC protocols. However, these measures are not often applied. When they are applied, they are often incorrect – even vulnerable. This could be discovered only during a security assessment of an ATM.

As a result, criminals do not need to tamper with the hardware, but simply exploit the vulnerabilities in the network communication between the ATM and the banking infrastructure.

How to stop the ATM breach

“The results of the survey show that even though ATM providers are now trying to develop machines with strong security features, many banks are still using older, insecure models. Thus, they are unprepared for criminals who actively compromise the security of these devices. This is the current reality, which can cause huge financial losses for banks and their customers. We believe that this situation is the result of a long-standing misconception, according to which cybercriminals are only interested in attacks against online banking services. "They are interested in these attacks, but they are also increasingly realizing the value of exploiting ATM vulnerabilities, because direct attacks against these devices significantly reduce the 'path' they have to cover before they can access real money," said Olga Kochetova, Security Specialist in the Penetration Testing Department at Kaspersky Lab.

Even though the security issues mentioned above probably affect many ATMs worldwide, this does not mean that the situation cannot be corrected. ATM manufacturers can reduce the risk of attacks on the machines by implementing the following measures:

  • First, it is necessary to revise the XFS standard with an emphasis on security, as well as to introduce two-factor authentication between devices and legitimate software. This will help reduce the likelihood of unauthorized cash withdrawals using Trojan programs and attackers gaining immediate control of ATM units.
  • Second, the implementation of «identified access provisioning» is necessary to eliminate the possibility of attacks through fake processing centers.
  • Third, the implementation of encrypted protection and integrity checking of the data transmitted between all hardware units and computers inside the ATM is necessary.

More information about the security issues of modern ATMs is available on the website Securelist.com.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS