Most ATM malware is designed to steal sensitive information. However, there are sophisticated threats that allow money to be stolen directly from the machines
Last week, at the Chaos Communication Congress (CCC), two German researchers revealed that they have identified malware that allows cybercriminals to gain control of ATMs and extract funds directly from them.
According to Wired, the malware is stored on a USB drive. The attacker goes to a vulnerable ATM running Windows XP, removes a piece of its chassis, and gains access to the machine's USB port.
It then installs the software, which forces the ATM to reboot. During the reboot, the malware rewrites the registers, and the attacker gains control of the machine.
After a few days, when the ATM is full of cash, the attacker goes back to it and uses a hidden menu to break the network connection and take the money.
The researchers, who spoke on condition of anonymity for security reasons, have not yet provided any details about the model of the ATMs targeted or the location where the malware. It is also uncertain whether the malware is widespread.

