
Hacking ATMs with just a text message may sound like something out of a movie, but it's a real thing.
A text message can be used to initiate a transaction by sending a command to the ATM's server. This is made possible by the way many ATMs are connected to the internet, using SMS or USSD codes to communicate with the server.
This method of hacking is often referred to as "smishing" or "phishing by SMS." It's a variation of traditional phishing attacks, but instead of using email, hackers use text messages to trick victims into revealing sensitive information.
To initiate a transaction, hackers need to know the victim's account details, which they can obtain through social engineering or by intercepting the victim's text messages.
ATM Vulnerabilities
ATM hacking is a growing concern, and it's getting easier to do with just a text message.
Decades-old techniques are still affecting modern machines, including ATMs.
A researcher, Josep Rodriguez, has found a way to exploit NFC systems, which many ATMs rely on, using a simple Android app.
This app can mimic credit card radio communications and trigger a buffer overflow, corrupting the machine's memory.
Rodriguez has used this technique to capture payment card info, inject malware, and even "jackpot" an ATM, making it spit out cash.
This is possible because many modern machines, including ATMs, still have vulnerabilities in their NFC systems' firmware.
In fact, 95 percent of ATMs run Windows XP software, which is about to be discontinued by Microsoft.
This will make it even easier for hackers to develop malware and exploit these machines.
The technique of using a text message to hack an ATM involves installing malware on the machine and then sending a text to a phone connected to the ATM via USB.
The phone turns the text into a network packet that commands the ATM to spit out cash.
This is a relatively simple process that can be repeated multiple times, making it a lucrative way for hackers to steal money.
For more insights, see: Bitcoin Atm Cash
Sources
- https://www.securityweek.com/atm-hackers-turn-text-messages-pull-bank-heists/
- https://gizmodo.com/hacker-breaks-atms-using-only-a-handy-cellphone-1847168966
- https://gizmodo.com/hackers-can-force-atms-to-spit-out-money-with-a-text-me-1551119933
- https://www.dailymail.co.uk/sciencetech/article-4727700/Cash-machines-hacked-just-FIVE-minutes.html
- https://www.zdnet.com/article/this-malware-turns-atm-hijacking-into-slot-machine-games/
Featured Images: pexels.com