ClearView IT Blog

ClearView IT has been serving the Phoenix area since 2005, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

Alert: Hackers Targeting ATMs to Get At Your Cash

b2ap3_thumbnail_atm_malware_400.jpgATMs are probably everyone’s favorite kind of computer. You swipe your card, enter in your PIN, and withdraw cash immediately. Many people forget that an ATM is simply a computer in disguise, though; one that can be infected with malware just as easily as any old PC can. A new type of ATM malware, GreenDispenser, is making its rounds in Mexico, and could potentially make its way to other countries if left unchecked.

ATM malware has been around for quite a while. In fact, a backdoor called Ploutus, which allowed for the exploitation of ATMs, also originated in Mexico. It allowed hackers to steal money from ATMs by sending commands either directly through the PIN pad or via a keyboard. It grew so advanced that hackers could simply send a text message to the machine and have it dispense cash. English localizations of Ploutus have surfaced, which hints that it was originally meant to spread beyond Mexico’s borders for use in other countries.

There are many other types of ATM malware out there, including Tyupkin, which was primarily used to infect ATMs in Eastern Europe, and Suceful, which locked cards inside the machine for later retrieval by hackers. However, all signs point to the fact that hackers need some physical access to the ATM in order to use it for malware exploitation, and this is further complicated by built-in security cameras that they are often equipped with. It’s suspected that the rise in chip encryption technology on credit cards is the cause of this increased ATM hacking activity.

The way that GreenDispenser works is by displaying an error message, claiming that the ATM is currently out of service. The hacker can bypass this message by entering a predetermined PIN that’s been coded into the malware. Additionally, the GreenDispenser malware continues to distinguish itself through several strange quirks. As explained by ComputerWorld:

Interestingly, GreenDispenser uses some type of two-factor authentication. After the hard-coded PIN is entered, the ATM will display a QR code, which the criminals probably scan with a mobile application in order to obtain a second, dynamically generated PIN. The second PIN unlocks an interaction menu on the ATM that gives attackers control over the cash dispenser. Another option on the menu allows criminals to uninstall the malware in a way that securely wipes it and makes it hard for forensics teams to later recover it.

Though card encryption is likely a leading cause for the increase in ATM malware, thereby making it much more difficult to gain information from card skimming, it’s suspected that another major reason hackers are targeting ATMs is because they often run outdated and vulnerable operating systems (like Windows XP). This only further proves that using operating systems that are past their expiration date can be detrimental and threatening to both your business and your users.

In the case of GreenDispenser, there’s not much for you to do to protect yourself. The victim is the bank or owner of the ATM. But if you do use an ATM, it doesn’t hurt to be aware of the security risks. Check to see if the ATM is under surveillance. If it’s pretty obvious that there are security cameras on the ATM, or it’s under regular supervision, there’s a smaller chance it’s been tampered with.

Since Windows 10 is now a major juggernaut in the business environment, there’s no reason your business needs to run machines that function off of antiquated software. Give ClearView IT a call at 866-326-7214 and ask our professional technicians what we can do for your organization’s computing infrastructure, including upgrading away from older Windows models, maintaining your technology solutions, and security best practices that mitigate the possibility of data theft.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Saturday, 05 July 2025
If you'd like to register, please fill in the username, password and name fields.

Captcha Image

Tag Cloud

Tip of the Week Security Technology Best Practices Business Computing Hackers Productivity Software Privacy Network Security Data Cloud Business User Tips IT Support Internet Hardware Innovation Malware Email Hosted Solutions Efficiency Workplace Tips Computer Google Microsoft Collaboration Android Phishing Business Management Cybersecurity IT Services Backup Data Backup Ransomware Smartphone communications Upgrade Smartphones Small Business Microsoft Office Mobile Devices Network Managed IT Services Communication Data Recovery Productivity Quick Tips Social Media VoIP Users Mobile Device Tech Term Automation Business Continuity Windows 10 Facebook Disaster Recovery Covid-19 Passwords Holiday Windows 10 IT Support Apps Browser Managed Service Cloud Computing Miscellaneous Outsourced IT Remote Work Internet of Things Managed Service Provider Data Management Government Saving Money Operating System Artificial Intelligence Managed IT services Networking Windows Gadgets Workplace Strategy Server Blockchain Remote Bandwidth WiFi Encryption Mobile Device Management Business Technology Information App Virtualization Spam Employee/Employer Relationship Budget Gmail Office Apple Two-factor Authentication Information Technology History Office 365 Health Data Security Analytics Wi-Fi Cybercrime BDR Conferencing Big Data Access Control Document Management Hacker Patch Management Save Money Remote Computing Remote Monitoring Compliance IT Management Help Desk Voice over Internet Protocol Training Cost Management Hacking Vendor Employer-Employee Relationship Retail Alert Data storage Money Hiring/Firing Customer Service Unified Threat Management Outlook Firewall Project Management Password Augmented Reality Data loss Word BYOD IBM Website Computing Vendor Management Hard Drive Mobile Office Search... Applications Managed Services Best Practice Legal Vulnerabilities Monitoring Healthcare Windows 11 Paperless Office Sports User Travel Social Antivirus Virtual Reality SaaS DDoS Social Engineering Maintenance Cryptocurrency Black Market Cleaning iPhone Chrome Education Cortana Robot Content Filtering Websites Mobility Meetings Router Mobile Computing Google Maps Scam Remote Workers Marketing The Internet of Things Data Breach YouTube Windows 7 Twitter Running Cable Free Resource VPN Law Enforcement Storage Laptop End of Support Printer Update How To Downtime Multi-factor Authentication Identity Theft Hack Safety Integration Notifications Images 101 Taxes Unified Communications Display Virtual Desktop Saving Time HIPAA Experience Google Docs Bluetooth Computers Bitcoin Employees Distributed Denial of Service Avoiding Downtime Office Tips Physical Security Telephone Private Cloud Memory Holidays Disaster Cooperation Excel Start Menu Video Conferencing Politics Downloads Computer Care Machine Learning Settings Lithium-ion battery Vulnerability Virtual Machines PowerPoint Computer Repair Software as a Service Administration Solid State Drive Professional Services Virtual Assistant Data Protection Processors Presentation Specifications Chromebook Drones IT Consultant Managed Services Provider Automobile Processor Customer Relationship Management Virtual Private Network Co-Managed IT Entertainment How To Wireless Technology Microchip Tech Terms Current Events Flexibility eWaste Managed IT Solutions Digital Digital Payment Supply Chain Management Value Reliable Computing Heating/Cooling SharePoint Writing Environment Emails Social Networking Smart Technology Fake News Worker Organization Windows XP Proxy Server Cyber security Smart Devices Service Level Agreement Computing Infrastructure Access Public Cloud Troubleshooting Remote Working Management Scalability Device security Time Management Wireless Headphones Text Messaging Microsoft Excel Proactive IT AI Trend Micro Administrator Tech Electronic Health Records Going Green Transportation Bring Your Own Device Audit Business Cards Spyware Digital Security Cameras File Sharing Error Wasting Time Modem Redundancy Supply Chain Music Bookmark eCommerce Term Surveillance Staffing Download Piracy Cache Videos Workers Business Owner Managing Costs IP Address HTML Unified Threat Management Nanotechnology SSID Workplace Browsers Botnet Google Play Development Upload Employer/Employee Relationships Rental Service Printing Software License Micrsooft Media CCTV Social Network Virtual Machine Flash Touchscreen Screen Reader Telephone Systems Emergency Scams Business Growth Reviews Computer Malfunction Data Analysis Optimization Security Cameras Recovery Trends Teamwork Competition Mobile Technology Vendor Mangement 2FA Samsung Inbound Marketing Data Storage Customer Resource management Hypervisor Devices Medical IT Banking Entrepreneur Cables Tip of the week Google Wallet Uninterrupted Power Supply Shopping Webcam LiFi Fileless Malware Documents Gamification SQL Server Messenger Application Company Culture Deep Learning Business Mangement Paperless Tablets PCI DSS Telephone System Licensing Regulations Business Intelligence Backup and Disaster Recovery Business Metrics Point of Sale Hosted Solution Electronic Payment Gig Economy Directions Humor Supercomputer Internet Service Provider Securty Content Azure Books Google Calendar Desktop Business Communications Virus Shortcuts Society Regulations Compliance Electronic Medical Records Managed IT Service Domains Accountants Language Database Motion Sickness Phone System Memes Net Neutrality Reading Comparison Monitors Google Drive Human Resources Visible Light Communication Be Proactive Windows 8 Financial Data Health IT Equifax Tactics Knowledge Hard Drive Disposal Corporate Profile Risk Management IT Google Apps Advertising Employer Employee Relationship Username Relocation Public Speaking Television Displays Telephony Work/Life Balance Workplace Strategies Freedom of Information Tech Support Cabling Telework Streaming Media Computer Accessories Startup Communitications Addiction Microsoft 365 Keyboard email scam Tablet Smartwatch G Suite Navigation Tracking Procurement Hard Drives Mouse Mobile Security VoIP intranet News FinTech User Tip In Internet of Things Legislation Evernote IT Assessment Wireless Network Management Hacks Shortcut Network Congestion CES Web Server

Blog Archive

Recent Comments

No comments yet.

Interested In A Free Consultation?