ClearView IT Blog

ClearView IT has been serving the Phoenix area since 2005, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

Alert: Hackers Targeting ATMs to Get At Your Cash

b2ap3_thumbnail_atm_malware_400.jpgATMs are probably everyone’s favorite kind of computer. You swipe your card, enter in your PIN, and withdraw cash immediately. Many people forget that an ATM is simply a computer in disguise, though; one that can be infected with malware just as easily as any old PC can. A new type of ATM malware, GreenDispenser, is making its rounds in Mexico, and could potentially make its way to other countries if left unchecked.

ATM malware has been around for quite a while. In fact, a backdoor called Ploutus, which allowed for the exploitation of ATMs, also originated in Mexico. It allowed hackers to steal money from ATMs by sending commands either directly through the PIN pad or via a keyboard. It grew so advanced that hackers could simply send a text message to the machine and have it dispense cash. English localizations of Ploutus have surfaced, which hints that it was originally meant to spread beyond Mexico’s borders for use in other countries.

There are many other types of ATM malware out there, including Tyupkin, which was primarily used to infect ATMs in Eastern Europe, and Suceful, which locked cards inside the machine for later retrieval by hackers. However, all signs point to the fact that hackers need some physical access to the ATM in order to use it for malware exploitation, and this is further complicated by built-in security cameras that they are often equipped with. It’s suspected that the rise in chip encryption technology on credit cards is the cause of this increased ATM hacking activity.

The way that GreenDispenser works is by displaying an error message, claiming that the ATM is currently out of service. The hacker can bypass this message by entering a predetermined PIN that’s been coded into the malware. Additionally, the GreenDispenser malware continues to distinguish itself through several strange quirks. As explained by ComputerWorld:

Interestingly, GreenDispenser uses some type of two-factor authentication. After the hard-coded PIN is entered, the ATM will display a QR code, which the criminals probably scan with a mobile application in order to obtain a second, dynamically generated PIN. The second PIN unlocks an interaction menu on the ATM that gives attackers control over the cash dispenser. Another option on the menu allows criminals to uninstall the malware in a way that securely wipes it and makes it hard for forensics teams to later recover it.

Though card encryption is likely a leading cause for the increase in ATM malware, thereby making it much more difficult to gain information from card skimming, it’s suspected that another major reason hackers are targeting ATMs is because they often run outdated and vulnerable operating systems (like Windows XP). This only further proves that using operating systems that are past their expiration date can be detrimental and threatening to both your business and your users.

In the case of GreenDispenser, there’s not much for you to do to protect yourself. The victim is the bank or owner of the ATM. But if you do use an ATM, it doesn’t hurt to be aware of the security risks. Check to see if the ATM is under surveillance. If it’s pretty obvious that there are security cameras on the ATM, or it’s under regular supervision, there’s a smaller chance it’s been tampered with.

Since Windows 10 is now a major juggernaut in the business environment, there’s no reason your business needs to run machines that function off of antiquated software. Give ClearView IT a call at 866-326-7214 and ask our professional technicians what we can do for your organization’s computing infrastructure, including upgrading away from older Windows models, maintaining your technology solutions, and security best practices that mitigate the possibility of data theft.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Monday, 05 May 2025
If you'd like to register, please fill in the username, password and name fields.

Captcha Image

Tag Cloud

Tip of the Week Security Technology Best Practices Business Computing Hackers Productivity Software Network Security Privacy Data Cloud Business User Tips IT Support Internet Hardware Innovation Malware Email Hosted Solutions Efficiency Workplace Tips Computer Google Microsoft Collaboration Android Business Management Cybersecurity Phishing IT Services Backup Data Backup Ransomware communications Smartphone Upgrade Smartphones Small Business Microsoft Office Mobile Devices Network Data Recovery Communication Managed IT Services Quick Tips Productivity Social Media Users VoIP Mobile Device Automation Tech Term Windows 10 Facebook Business Continuity Passwords Holiday Covid-19 Disaster Recovery Apps IT Support Browser Managed Service Windows 10 Cloud Computing Outsourced IT Miscellaneous Internet of Things Managed Service Provider Remote Work Data Management Government Saving Money Operating System Networking Workplace Strategy Windows Gadgets Artificial Intelligence Managed IT services Blockchain Bandwidth WiFi Encryption Server Mobile Device Management Information Remote App Virtualization Spam Business Technology Budget Gmail Employee/Employer Relationship Office Apple Two-factor Authentication Information Technology History Office 365 Analytics Cybercrime Wi-Fi Conferencing Access Control Data Security Big Data BDR Health IT Management Save Money Training Remote Computing Compliance Patch Management Help Desk Vendor Hacking Cost Management Remote Monitoring Employer-Employee Relationship Voice over Internet Protocol Document Management Hacker Managed Services Hiring/Firing Customer Service Unified Threat Management Firewall Data loss Outlook Password Augmented Reality Word BYOD IBM Website Computing Vendor Management Hard Drive Applications Project Management Search... Vulnerabilities Best Practice Legal Retail Mobile Office Alert Data storage Money Free Resource Google Maps Sports Travel User Social Scam SaaS DDoS Virtual Reality How To Social Engineering Cryptocurrency Black Market VPN iPhone Cleaning Chrome Education Cortana Robot Update Content Filtering Data Breach Router Mobile Computing Paperless Office Antivirus The Internet of Things Marketing YouTube Maintenance Running Cable Twitter Windows 11 Law Enforcement Monitoring Storage Laptop End of Support Printer Healthcare Websites Remote Workers Meetings Mobility Windows 7 Virtual Private Network Virtual Desktop Google Docs Telephone HIPAA Experience Bluetooth Distributed Denial of Service Current Events Office Tips Private Cloud Excel Solutions Memory Disaster Integration Tech Terms Images 101 Display Managed IT Politics Machine Learning Virtual Assistant Settings Lithium-ion battery Digital Employees PowerPoint Administration Solid State Drive Taxes Avoiding Downtime Processors Holidays Presentation Specifications Processor IT Consultant Chromebook Drones Cooperation Video Conferencing Automobile Physical Security Customer Relationship Management Co-Managed IT Virtual Machines Computer Repair Entertainment How To Multi-factor Authentication Wireless Technology Microchip Flexibility Professional Services eWaste Start Menu Computer Care Downloads Downtime Vulnerability Saving Time Hack Safety Identity Theft Software as a Service Managed Services Provider Notifications Bitcoin Unified Communications Data Protection Computers Download Administrator Supercomputer Piracy Text Messaging Proactive IT Google Calendar Term Google Apps Virus Telework HTML Bring Your Own Device Motion Sickness Microsoft 365 Cables Browsers Smartwatch Nanotechnology Communitications Google Drive Upload Procurement Software License Music Comparison Google Play Social Network FinTech Staffing Business Owner Point of Sale IP Address Knowledge Data Analysis CES Corporate Profile Screen Reader IT Assessment Telephony Trends Supply Chain Management Botnet Employer Employee Relationship Mobile Technology Value Television Security Cameras Micrsooft Customer Resource management Organization Cabling Devices Cyber security Rental Service Shortcuts G Suite Tip of the week Flash Fileless Malware Tablet Smart Devices VoIP Gamification Remote Working Tracking Company Culture Telephone Systems Business Growth Mouse Competition Telephone System AI Regulations Trend Micro Recovery Be Proactive Inbound Marketing Web Server Transportation Directions Digital Security Cameras Backup and Disaster Recovery Electronic Health Records SharePoint Content LiFi Digital Payment Desktop Wasting Time Banking Entrepreneur Google Wallet Application Deep Learning Electronic Medical Records Worker Accountants eCommerce Documents Messenger Modem Workplace Strategies Access Database Surveillance Business Intelligence Videos Time Management Electronic Payment Public Cloud Managing Costs Business Metrics Hosted Solution SSID Health IT Equifax Securty Books Spyware Tactics Development Hard Drive Disposal Employer/Employee Relationships Domains Language Society Audit Media Username File Sharing Virtual Machine Phone System Reading Freedom of Information Smart Technology Monitors Visible Light Communication Redundancy Reviews Startup Optimization Cache Addiction email scam Teamwork Windows 8 Navigation 2FA Unified Threat Management Data Storage Workers Mobile Security Hypervisor Relocation News Medical IT Public Speaking Displays Advertising User Tip Shopping Legislation Network Management Streaming Media CCTV SQL Server Computer Accessories Work/Life Balance Tech Support Printing Evernote Paperless Keyboard Touchscreen PCI DSS Licensing Computer Malfunction Fake News Supply Chain Hard Drives Emergency Proxy Server Gig Economy Emails Humor Vendor Mangement Service Level Agreement Internet Service Provider In Internet of Things Computing Infrastructure Azure intranet Business Communications Shortcut Network Congestion Management Regulations Compliance Samsung Device security Managed IT Service Wireless Hacks Reliable Computing Webcam Microsoft Excel Workplace Heating/Cooling Writing Environment Uninterrupted Power Supply Wireless Headphones Memes Business Mangement Going Green Net Neutrality Windows XP Business Cards Social Networking Tech Human Resources Error Financial Data Tablets Troubleshooting Scalability Scams Bookmark Risk Management IT

Blog Archive

Recent Comments

No comments yet.

Interested In A Free Consultation?