Tuesday, November 12, 2024
HomeSecurity NewsATMJackpot - New ATM Malware Steal Your Money From ATM using ATM...

ATMJackpot – New ATM Malware Steal Your Money From ATM using ATM Jackpotting Technique

Published on

Malware protection

New ATM Malware called ATMJackpot that is capable of dispensing large amounts of cash from the ATM Machine using ATM Jackpotting method.

Previously discovered ATM Jackptting Malware compromise the ATM by installing the malicious software and sophisticated hardware to pull out the cash.

Based on the Binary, researchers discovered this ATM malware originated from Hong Kong as 28th March 2018.

- Advertisement - SIEM as a Service

A few Months before sophisticated ATM skimming called “Shimmers”  targeted chip-based credit and Debit cards to steal your entire card information form POS(Point-of-sale) terminal.

Also, Attackers inject an another ATM Malware called Ploutus.D inject into the ATM machine and performing various Task

This newly Spreading ATM malware has a smaller footprint with a kind of small simple graphical user interface.

a simple graphical user interface

This Malware interface contains hostname along with the service provider information such as cash dispenser, PIN pad, and card reader information.

How Does This ATM Malware Works 

This ATM Malware propagates via physical access by an attacker using USB and also spreading via a network by downloading the malware on to already-compromised ATM machines.

Initially, windows class name called ‘WIN’ registered by the ATMJackpot malware that leads to handle all the malware activities.

According to netskope,  After registering a window class, the malware creates the window, populates the options on the window, and initiates the connection with the XFS manager

Later ATMJackpot malware starts it monitoring an operation of the events from different service providers and finally execute commands.

It using  3 Different commands to perform its malicious operation in the targeted ATM

1.Malware reads the data from PIN pad asynchronously using WFSAsyncExecute API

Read data from PIN Pad

2.Malware has the functionality to dispense cash

Dispense cash

3.Malware also has the functionality to eject the card

Eject ATM card

You can Also check the  Advanced ATM Penetration Testing Methods that help prevent the ATM Based Attacks.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

10 Best DNS Management Tools – 2025

Best DNS Management Tools play a crucial role in efficiently managing domain names and...

Sweet Security Announces Availability of its Cloud Native Detection & Response Platform on the AWS Marketplace

Customers can now easily integrate Sweet’s runtime detection and response platform into their AWS...

Researchers Detailed Credential Abuse Cycle

Cybercriminals exploit leaked credentials, obtained through various means, to compromise systems and data, enabling...

New Android Malware SpyAgent Taking Screenshots Of User’s Devices

SpyAgent, a newly discovered Android malware, leverages OCR technology to extract cryptocurrency recovery phrases...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Critical PDF.js & React-PDF Vulnerabilities Threaten Millions Of PDF Users

A new critical vulnerability has been discovered in PDF.js, which could allow a threat...

LayerX Security Raises $26M for its Browser Security Platform, Enabling Employees to Work Securely From Any Browser, Anywhere

LayerX, pioneer of the LayerX Browser Security platform, today announced $24 million in Series...

Email Header Analysis – Verify Received Email is Genuine or Spoofed

Email Header Analysis highly required process to prevent malicious threats since Email is...