Hackers are targeting ATMs in India with new malware that steal data




A banking malware named ATMDTrack  has been active in India since late last summer, in a  kaspersky report .

Allegedly State sponsored Hackers from North Korean government have developed a new strain of malware that has been used to record and steal data from cards inserted into ATM machines in India.

Further analysis of the malware by the Moscow-based cybersecurity firm found the samples to be part of a bigger remote access trojan (RAT) called DTrack.

Calling it a spy tool to attack financial institutions and research centers in India, the experts said the malware strains shared “similarities with the DarkSeoul campaign, dating back to 2013 and attributed to the Lazarus group.”

The DTrack RAT was detected as recently as this month, the researchers noted.




Collecting key logs and browser histories

The threat actors behind DTrack obfuscated their malicious code in an innocuous executable file that was protected behind encryption barriers in a dropper used to install the malware.

Aside from disguising itself as a harmless process, the malware can perform a number of operations such as:

  • .Keylogging
  • .Retrieving browser history
  • .Gathering host IP addresses, information about available networks and active connections
  • .Listing all running processes
  • .Listing all files on all available disk volumes

The collected data was then archived as a password-protected file that’s either saved to the disk or sent to a command-and-control server.

Classifying ATMDTrack as a subset of the DTrack family, the researchers said the developers behind the two malware strains are the “same group of people.”

Given the sophistication of the modus operandi, it’s recommended that target organizations beef up their network and password policies and monitor network traffic for any suspicious behaviour.

The kaspersky report also says the vast amount of DTrack samples that they found shows that the Lazarus group is one of the most active APT groups in terms of malware development, And they see that this group uses similar tools to perform both financially-motivated and pure espionage attacks.

I feel Banks need to go extra mile for searching and weeding out this malware from the ATM’s . ATM have come out as the last mile vulnerability in Indian banking industry due to usage of vulnerable OS and lack of physical security. 

Comments

  1. I want to shear a life changing story with everyone who cares to read this testimony. Blank atm cards are real and are effective all over the world. my name is Gorge Judy i live in SPAIN . I got this card from [skylink technology] a month ago. this card has really help me pay my debts and now i am free from all financial problems. I no this is hard to believe , but i never knew there was this kind of card until i got one. This card withdraw more than €6000 daily and it is very easy to use. But you have to be very careful in other not to be caught by the police because it is illegal. If you want more information on this card and how to get one just contact the hackers by this address
    skylinktechnes@yahoo.com or whatsapp +1(213)328–0248

    ReplyDelete

Post a Comment

Popular posts from this blog

What to do when police does not take your FIR?

Consumer Dispute resolution under the Telecom Act 2023

When can Police Arrest you in Cyber crime: Explanation with Case Laws