FireEye researchers have identified a new generation of malware that targets automated teller machines (ATMs), using a series of advanced processes that can block credit cards inside the machine and release them only when the malware's operator manages to steal the data they need without being detected.
This new malware has been named SUCEFUL by researchers, as its creators have misspelled the word “Successful” in the message that appears after the successful execution of each software function.
And while in early 2013 and into 2014, advanced ATM malware such as Ploutus and PadPin were used globally to help criminals empty ATMs, the situation has now changed, with the new strain SUCEFUL representing, in 2015, a significant advance in the art of designing ATM malware.
One of the most sophisticated ATM malware ever detected
According to FireEye researchers, SUCEFUL comes with a wide range of capabilities and features, which allow criminals to take full control of an ATM.
Analysis of the SUCEFUL code reveals that criminals can infect ATMs, regardless of brand or platform, and have the ability to:
a) read data from the magnetic black stripe of the card,
b) read data from the card chip,
c) block cards inside ATMs,
d) release the cards on demand,
e) disable ATM security sensors and
f) control the operation of the malicious software through the ATM's numeric keypad.
As the researchers point out, all of the above functions are possible because the programmers who designed the malware are not simply hackers exploiting weaknesses in cash machine vendors' software, but instead have closely studied the design of ATMs in general and have created an advanced malware that acts platform-independently, imitating the software management programs present in ATMs and used primarily by maintenance crews.

