by admin • November 19, 2014
Josep Verdura 150x150 pp Tyupkin virus affecting ATM with which you operate
Josep Verdura - Security Analyst Vintegris
Russian forensic investigators led the operation to achieve unravel attacks targeting ATMs worldwide conducted by cybercriminals
During the investigation, the researchers discovered that the malware Tyupkin was manipulated to infect ATMs and provide attackers with the task of stealing the money by direct manipulation, which reported millions of dollars of profit for criminals.
Attack Technique
Cybercriminals defined two distinct phases of work. One related to physical access to ATMs to insert a bootable CD to install the malware Tyupkin.
On bootup, the ATM is under infected under their control and malware running in an infinite loop waiting for a specific order.
When analyzing intelligence phishing model it was found that malware Tyupkin -únicamente- accepts commands at defined times between Sunday and Monday night days.
During these time windows released, attackers were fully operational for stealing money from each infected ATM.
Through a unique combination of digits based on random numbers generated each session, which certified that no user accidentally discovered or benefit fraud, also gave assurance for cybercriminals "mules" who collected money does not try to make the operation of your account as required by code receiving phone to operate in that window of time.
When keys are introduced into the ATM, the screen you could see the detail of the amount of cash that was stored on each cartridge, inviting the user to select the cassette to steal.
Once the operation is the cashier which automatically delivers 40 notes of the selected cassette.
This type of transaction represents the natural evolution of cybercrime more sophisticated cybercriminals and clearly attacking financial institutions.
Josep Verdura - Security Analyst Vintegris
Tyupkin virus affecting ATM with which you operate vintegris.info
Russian forensic investigators led the operation to achieve unravel attacks targeting ATMs worldwide conducted by cybercriminals.
http://vintegris.info/tyupkin-010101/
traducido por Federico Dilla
Tyupkin el virus que afecta a los ATM con los que Usted opera
by admin •
http://vintegris.info/tyupkin-010101/
traducido por Federico Dilla
Investigadores forenses rusos lideraron la operación para lograr desentrañar los ataques dirigidos a varios cajeros automáticos de todo el mundo realizados por ciberdelincuentes.