HomeSecurityEverything you need to know about ATM Hacking

Everything You Need to Know About ATM Hacking

A comprehensive research report published last year revealed that most ATMs can be hacked in 20 minutes or less. Even more frightening, 85% of the ATMs tested for the study allowed an attacker to gain access to the network, and another 58% had vulnerabilities in network components or services that could be exploited to control the ATM from a remote location.

All of this simply means that ATMs are much more vulnerable than we thought. When you consider that they not only hold huge amounts of cash but also contain valuable user data, this can be a pretty scary thought.

We searched the Dark Web to see what information is available around the various ATM accident response strategies. We found a variety of information about the various strategies and tried to incorporate the basics into this article, in the hopes that it will help readers become more aware of what is out there and how to stay safe.

ATM

Method 1: ATM Malware Card

This is probably one of the most popular methods used by ATM hackers to exploit vulnerabilities. There are sites on the dark web that deliver the entire malware kit to the customer, which includes the ATM Malware Card, PIN Descriptor, Trigger Card, and a Guide.

Once the malware is installed on the ATM using the ATM Malware Card, all of the customers’ debit card information can be retrieved from the machine. The hackers then use the Trigger Card to dispense cash from the ATM. Overall, this is one of the most popular methods on the dark web and comes with quite detailed, step-by-step instructions on how to perform it. This method is supported on machines running Windows XP.

Method 2: USB ATM Malware

This is another prevalent method for machines running Windows XP. It allows hackers to distribute all the cash from the ATM by using the USB hosted with Malware software to infect the machine.

Method 3: Hacking ATM Devices

There are many ATM Skimmer shops on the dark web that offer various ATM Hacking devices such as EMV Skimmer, GSM Receiver, ATM Skimmer, POS, Gas Pump, Deep Insert, etc. Many shops offer a package of these different devices together.

These devices have a range of applications. On the one hand, there is a special class of Deep Insert devices that are attached to ATM machines to extract sensitive financial information from users. At the same time, there are some packages where the attacker does not need to be physically present at the ATM to install malware. Devices like Antenna allow hackers to carry out their attacks remotely, which makes it much harder to track down the perpetrators.

These stores are available on the dark web and continue to be updated with newer devices, such as terminals, upgraded Antenna, custom-made ATM Skimmers, RFID Reader/Writer, and so on.

Method 4: Prepaid Cards

There are dark web shopping sites that offer both Bank Fullz and physical bank cards on their platform. While Fullz cards are used for online transactions, physical cards can be used at ATMs. Some sites also offer prepaid credit cards, and the price of the card is apparently proportional to the available balance on the card.

Method 5: Training seminars and case studies

There are various tutorials and real-world case studies available on forums on the Dark Web. For example, there is a detailed tutorial on a hacking forum that discusses how bank accounts can be compromised using Botnets. Many tutorials containing detailed instructions on how to hack an ATM are also available for sale on various Dark Web stores, typically selling for $100 each.

Method 6: Ploutus-D

The Ploutus-D malware has been used in recent ATM attacks. The malware compromises key components of a well-known multi-agent ATM software and takes control of hardware devices such as the cash dispenser, card reader , and pin pad. This means that any hacker can dispense all the cash in the machine in a matter of seconds. The source code for Ploutus-D along with detailed instructions are now being sold on various dark web marketplaces.

Summing up

It’s hard to imagine that ATMs that are part of our everyday lives could actually be vulnerable to attack. However, as we saw during our research, ATM hacking is becoming increasingly common, especially with the availability of devices that allow hackers to access ATMs remotely. Since banks typically have the same configuration across a large number of ATMs, a single successful attack can usually be replicated on a much larger scale.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS