In 2009, a malware called “Skimer” emerged. Skimer is essentially malware that gives a hacker full access to an ATM, without having to install any physical hardware, such as a card reader. According to new research from Kaspersky Lab, the malware has become much more powerful.
Kaspersky discovered the latest version of Skimer this month after investigating fraudulent withdrawals at a bank. While the bank was unable to find any evidence that it had been attacked, the security firm found that a new version of Skimer had been used. The new version was so improved that it was harder to detect. The malware also allowed hackers to take full control of any ATM.
Hackers start by installing a file called Backdoor.Win32.Skimer. The malware hides in the ATM code and lies in wait until the hacker runs it by inserting a specific card.
Kaspersky explains what will happen next:
The Skimer graphical interface appears on the screen only after the card has been extracted and if the hacker enters the correct session key (pin).
With the help of a menu that appears, the hacker can run 21 different commands, such as distributing money (40 accounts at a time), collecting data from cards inserted into the ATM, self-deleting the malware, updating the malware (from the updated malware code embedded in the card chip), etc.
Also, while collecting the bank customers' card data, the Skimer stores the data and PINs on the hacker's card chip.
Traditionally, skimmers are simple devices that can intercept a transaction. At ATMs, they can record your credit card numbers, and with the help of additional technology, such as cameras or keypad overlays, they can also intercept PIN codes. If you know where to look, you can see if an ATM has been hacked, although the hardware hackers use is becoming increasingly sophisticated.
Skimer, on the other hand, is a bit more sophisticated. It can gain access to ATMs either through physical access, such as a traditional card reader, or through the bank's internal network. Kaspersky warns that ATMs infected with Skimer are not easily recognizable and difficult to detect:
In most cases, criminals choose to wait for the data to be collected so they can make copies of the cards later. With these copies, they go to a different, uninfected ATM and withdraw money from customers’ accounts. This way, criminals can ensure that the infected ATMs will not be discovered soon.
But let's see the Skimer in action:
