It seems like it's incredibly easy to hack an ATM these days, and security researchers at Symantec report that Windows XP 's Microsoft, the operating system the machines run on, is making the problem worse.
We do not know if Microsoft will make a special agreement with the Banks for further support of its operating system, or if the Banks will change all their systems. One thing is certain. Something must be done because everyone's deposits are at risk (so as not to be misunderstood, we favor those who have them).
This week, security researchers at Symantec blogged about a new technique that emerged in Mexico that uses text messages (SMS) to give a hacker access. It's not as simple as it sounds.
The method from the beginning?
The first step in this method involves installing a known malware called Ploutus on a bootable machine (we have reported on Ploutus for some time now). This requires the hacker to crack the machine and use a CD-ROM or USB stick to infect the operating system.
In the past, the attack was carried out using an external keyboard. With the advanced method, the hacker simply connects a smartphone to the machine via USB and sends a text message to the phone. The phone converts the text into a network packet that controls the ATM and forces it to withdraw all its cash.
It's a very clever method. The mobile phone allows hackers to carry out multiple attacks without having to break into the machine each time. Instead, all they need is a supermarket trolley to transport the money, as Symantec.
As the security firm on its blog, what makes it easier for hackers is the fact that 95% of machines run Windows XP, which Microsoft is set to retire. And that will make it even easier for hackers to develop malware and other techniques to exploit ATMs.
More information about the attack and videos on Symantec's blog
Source: secnews.gr
