TMitch Fileless malware: One day, bank employees discovered an empty ATM: no money, no sign of physical interaction with the machine, and no malware. After Kaspersky Lab experts spent a lot of time investigating this mysterious case, they were able not only to understand the cybercrime tools used for the robbery, but also to reproduce the attack themselves, discovering a breach in the bank’s security system. 
In February 2017, Kaspersky Lab published the results of an investigation into mysterious fileless attacks against banks: criminals were using memory-hopping malware to “infect” banking networks. But why would they do this?
The “ATMitch” case gave us the big picture.
The investigation began after the bank’s forensic experts recovered and shared with Kaspersky Lab two files containing malware logs from the ATM’s hard drive (kl.txt and LogFile.txt). These were the only files left after the attack: the malicious executables could not be recovered because the cybercriminals had wiped the malware after the robbery. But even this small amount of data was enough for Kaspersky Lab to conduct a successful investigation.
Erase / rewind
Within the logs, Kaspersky Lab were able to identify pieces of information in plain text, which helped them create a YARA rule for public malware storage and find a sample. YARA rules – basic search strings – help analysts find, group, and categorize related malware samples and establish connections between them based on patterns of suspicious activity on systems or networks that have similarities.
After a day of waiting, the experts found a desired malware sample – “tv.dll”, or “ATMitch”, as it was later named. It was detected free twice: once in Kazakhstan and once in Russia.
This malware was installed and executed remotely on an ATM from within the target bank: via remote management of ATM machines. After being installed and connecting to the ATM, the ATMitch malware communicates with the ATM as if it were legitimate software. This allows attackers to execute a list of commands, such as collecting information about the number of banknotes in the ATM’s cassettes. It also allows criminals to dispense money at any time, with the push of a button.
Typically, criminals start by obtaining information about the amount of money a machine has. After that, a criminal can send an order to dispense any number of bills from any cassette. After withdrawing money in this strange way, the criminals only need to grab the money and run. An ATM robbery like this takes just a few seconds!
Once the ATM robbery is carried out, the malware erases its traces.
Who is behind the attacks?
It is not yet known who is behind the attacks. The use of open source exploits, common Windows utilities, and unknown locations during the first stage of operation make it almost impossible to identify the group responsible. However, the “tv.dll” used in the ATM stage of the attack contains a Russian-language source, and known groups that could fit this profile are GCMAN and Carbanak.
“The attackers may still be active. But don’t panic! Combating this type of attack requires a specific set of skills from the security specialist protecting the target organization. Successfully breaching and exfiltrating data from a network can only be accomplished with common and legal tools. After the attack, criminals can wipe all data that could lead to their detection without leaving any trace whatsoever. To address these issues, forensic evidence derived from memory is crucial for analyzing malware and its operations. And as our case demonstrates, carefully directed incident response can help solve even the most ‘perfect’ cybercrime,” said Sergey Golovanov, Principal Security Researcher at Kaspersky Lab.
Technical details and Indicators of Compromise are also provided to Kaspersky Intelligence Services customers .
