back to article 'Self-deleting' Mexican ATM malware let sneaky miscreants slurp cash

Security researchers have lifted the lid on a new ATM malware strain, dubbed GreenDispenser, which gives crooks the ability to walk up to a compromised machine and drain its cash. When installed, GreenDispenser displays an “out of service” message on the ATM – but attackers who enter the correct pin codes can then drain the …

  1. Anonymous Coward
    Anonymous Coward

    Self deleting code ? Soooooo 1980s ...

    Done before

    "...

    It had a neat extra trick that after a machine was fully infected, it *de*infected the machine until clean. Really got a few heads scratching there.

    ..."

  2. Spender

    Just don't ever use an ATM in Mexico

    It seems like the miscreants have penetrated the ATM suppliers good'n'proper.

    Here's a little bit of fun with Mexican ATMs:

    http://krebsonsecurity.com/2015/09/whos-behind-bluetooth-skimming-in-mexico/

  3. CP/M-80

    Interesting. The malware authors must have a pretty good knowledge of the operating system, hardware, and they have access to the machines- presumably without drilling the case to access a USB socket. It seems like this needs someone with inside knowledge?

    Whilst stealing money is of course very wrong, I was impressed by idea of displaying a QR code, that's neat.

    1. Anonymous Coward
      Anonymous Coward

      Don't most of them run hideously outdated versions of windows, and the only 'protection' they use is a lock to cover access to the ports on the machine.

      1. Anonymous Coward
        Anonymous Coward

        Even if the tech is really that bad...

        You still have to unlock, or break into the device from behind which is really quite obvious in many locations. Suggests that the person changing the till-rolls/cash etc have key, knowledge, and perhaps a stake in (or are blackmailed by) the fraudsters.

        You certainly could not do this without being seen as suspicous without considerable difficulty otherwise...

        1. Hans 1

          Re: Even if the tech is really that bad...

          No, it is not that hard. On a great number, all you do is come along dressed in blue overalls, a toolbox and remove the cover on the front panel. This works for many ATM's, since they are using some outdated strain of XP, all you need is a specifically crafted jpg and the thing is 0wned. others just hook up a keyboard and USB drive and let the fun begin ... if you wanna get to the management ui, most have default passwords UNCHANGED, from there, reboot the bugger -> 0wned.

          Easy really ...;-)

  4. NanoMeter

    What if these incredibly creative criminals

    used their wits for the better good of society instead of this? No, won't happen.

    1. Mark 85

      Re: What if these incredibly creative criminals

      It depends on how they (not us) define "good". They strike out at the "evil banks".. get some cash and spend it which helps the local economy. It's still wrong, but then we're looking at one of the lands of drug lords, drug wars, and general mayhem and killings all in the name of "power". Just a few degrees worse than most of the "civilized" countries....

      I gottta' find the off switch for my cynic button.

    2. Chozo

      Re: What if these incredibly creative criminals

      "used their wits for the better good of society instead of this?"

      Surely bank robbery benefits everybody by putting large amounts of cash back into circulation. The economy is stimulated, small businessmen prosper and so contributes to the health and stability of society.

      1. Gene Cash Silver badge

        Re: What if these incredibly creative criminals

        Hm. OK, "Chozo" give it up, we know your real name is "Worstall"...

        1. Trevor_Pott Gold badge

          Re: What if these incredibly creative criminals

          Are you kidding? Worstall would never advocate something that actually benefited the people instead of the 1%. He would want anyone who did anything that ever threatened the utter dominance of the 1% melted in public, all while claiming that it was "for the greater good". Then he'd demand deregulation so that the 1% could stimulate the economy by paying us all less all through the magic of "the invisible hand".

          Robbing the rich in order to buy shiny shiny thus actually enriching the majority is essentially Worstall's antiparticle.

  5. Anonymous Coward
    Anonymous Coward

    Maybe the ATM manufacturers should have continued using OS/2 instead of changing to windows.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like