Hacking into automated teller machines (ATMs) is certainly nothing new. Until now, it was known that this was done using ATM Skimmers, devices that were placed in the ATM and copied the withdrawal card when the user inserted it. However, according to information, hackers have developed a special technique that allows them to steal money through ATMs. The technique is based on the use of USB and the installation of malicious software in the ATMs!
Most of the ATMs in European banks - including Greek ones - have the Windows XP operating system (ed., haven't the banks been informed that Windows XP is now End-Of-Life by Microsoft?). As is known, Windows XP is particularly vulnerable to malware attacks. Like home computers, ATMs have USB ports that are hidden behind the ATM casing.
A German researcher announced at the Chaos Computing Congress, held in Hamburg, Germany, that hackers are now drilling holes in the ATM casing to gain physical access to the USB port, through which they install malware on the ATM terminal! The malware installs a backdoor in the ATM that allows full access to its functions. As the researchers explained, “The backdoor allows access to the ATM Interface by typing a 12-digit code. The Interface allows withdrawals, as well as access to the total amount available in the ATM. Knowing how many and what kind of banknotes the ATM has, they can only withdraw large banknotes,” the researcher says.
https://www.youtube.com/watch?v=0c08EYv4N5A
Once the cybercriminals have stolen the ATM money, they patch the vulnerability to prevent someone else from using the vulnerability in the same way to withdraw cash. This suggests that the cybercriminals using this methodology are highly experienced and have a high level of knowledge of the mechanisms of automated teller machines, according to the researchers.
The malware does not appear to steal customer PINs or sensitive data so far.
It is not known whether Greek Banks have this weakness in the automatic withdrawal systems they use. The Association of Hellenic Banks and the Bank of Greeceshould immediately investigate this methodology and issue an announcement, if it finds that the method is applicable to ATMs in Greece. The security departments of the Banks should IMMEDIATELY check whether the full upgrades of the operating systems of their ATMs have been applied, as well as disable the use of USB ports in case it allows external boot or application installation!



