Security researchers have discovered a new malware family that targets ATMs in Mexico, allowing attackers to enter two special PIN codes into the target machine and empty its cash reserves.
The malware was first spotted and analyzed by security experts at Proofpoint, who found similarities to the ATM malware Padpin, which primarily targets Russia and Eastern Europe and was detected by Kaspersky researchers in October 2014.
The new ATM malware, also known as GreenDispenser, carries advanced features that make it extremely difficult to detect, and also has the ability to deactivate itself after a certain period of time so as not to be noticed.
According to Proofpoint, installing the malware requires physical access to the ATM, which leads researchers to believe that insiders may be involved, or that bank staff are unable to detect modifications made to the ATM during the malware installation.
Fortunately, there is a simple way to identify infected ATMs, which display the fake message “Temporally out of service” which in Spanish means “Temporarily out of service”.
Once installed, GreenDispenser uses the XFS middleware, allowing attackers to interact with the malware code from the ATM PIN keypad. This functionality is critical because the malware is designed to empty ATMs upon receiving specially crafted commands, which can only be issued by attackers after successful authentication.
Attackers use two PIN codes to identify themselves
Identification is done by typing a PIN, which is hard-coded into the malware code, while a secondary PIN is then required, which according to Proofpoint researchers is obtained from the barcode label present on each ATM.
The malware also comes with a deep erase feature, which attackers can exploit to erase their tracks after they have emptied the ATM.
Finally, in case the ATM cannot be accessed for various reasons, the malware has a secondary protection measure, which is hard-coded into its source code. Specifically, every time GreenDispenser starts, it checks the year and month, and if the dates do not match the values passed to its code, then it does not execute. This mechanism allows it to remain hidden until it is upgraded by the attackers to a newer version, or until it is deleted by them later in order to cover their tracks.

