#ATMHacking
Hackers Use 4G-Connected Raspberry Pi to Breach Bank’s ATM Network #ATMHacking #Banks #GroupIB
Hackers Use 4G-Connected Raspberry Pi to Breach Bank’s ATM Network
  A cybercriminal group has used a surprising method to infiltrate a bank’s internal systems, by planting a tiny Raspberry Pi computer inside the bank’s network. The attackers reportedly used the device to gain access to critical parts of the bank’s infrastructure, including systems that control ATM transactions. The incident was reported by cybersecurity firm Group-IB, which called the approach “unprecedented.” The attackers managed to bypass all external cybersecurity defenses by physically placing the small computer inside the bank’s premises and connecting it to the same switch that handles ATM traffic. This gave them direct access to the bank’s internal communications. The Raspberry Pi was fitted with a 4G modem, which allowed the hackers to control it remotely over mobile networks, meaning they didn’t need to be anywhere near the bank while carrying out their attack. The main target was the bank’s ATM switching server — a system responsible for processing ATM transactions, and its hardware security module (HSM), which stores sensitive information like encryption keys and passwords. By gaining access to these systems, the attackers hoped to manipulate transaction flows and extract funds undetected. The hacking group behind the attack, known in cybersecurity circles as UNC2891, has been active since at least 2017. They are known for targeting financial institutions and using custom-built malware, especially on Linux, Unix, and Solaris systems. In this latest attack, the group also compromised a mail server within the bank to maintain long-term access. This mail server had continuous internet connectivity and acted as a bridge between the Raspberry Pi and the rest of the bank’s network. A monitoring server, which had access to most internal systems, was used to route communications between the devices. During their investigation, Group-IB researchers noticed strange behavior from the monitoring server. It was sending signals every 10 minutes to unknown devices. Further analysis revealed two hidden endpoints, the planted Raspberry Pi and the compromised mail server. The attackers had gone to great lengths to stay hidden. They disguised their malware by giving it the name “lightdm,” which is the name of a legitimate Linux display manager. They even mimicked normal command-line behavior to avoid raising suspicion during forensic reviews. To make detection harder, the hackers used a lesser-known technique called a Linux bind mount, typically used in system administration, but now added to the MITRE ATT&CK cybersecurity database under “T1564.013.” This allowed the malware to function like a rootkit — a type of software that hides its presence from both users and security tools. This incident is your call to be hyperaware of how attackers are becoming more creative, blending physical access with advanced software tactics to infiltrate secure environments.
dlvr.it
August 6, 2025 at 4:39 PM
📌 Two Florida men charged with stealing over $100,000 by hacking ATMs in Michigan. Arrested in Minnesota with stacks of cash. #CyberSecurity #ATMHacking https://tinyurl.com/2cvsux9p
Florida Men Arrested for ATM Jackpotting in Michigan: A Deep Dive into the Cyber-Physical Threat
ATM jackpotting is a sophisticated form of cybercrime that combines physical and digital attacks to manipulate ATMs into dispensing cash illegally. The recent case involving two Florida men accused of stealing over $100,000 from ATMs in Michigan highlights the ongoing threat posed by such attacks. The suspects were arrested in Minnesota with stacks of cash, indicating a well-planned and executed operation. Technically, ATM jackpotting often involves the use of malware or exploit kits that target vulnerabilities in the ATM's operating system or software. Attackers may gain physical access to the ATM to install malicious software or connect unauthorized devices. Once the malware is in place, it can be triggered remotely or via a specific sequence of commands to force the ATM to dispense cash. The implications of such attacks are far-reaching. For financial institutions, the loss of cash is just one aspect; the reputational damage and loss of customer trust can be even more significant. Moreover, ATM jackpotting can be part of a larger cybercrime operation, with stolen funds being laundered through various channels. The impact on the cybersecurity landscape is clear: financial institutions must adopt a multi-layered security approach. This includes regular software updates and patches, strong encryption, and robust physical security measures. Surveillance cameras, tamper-evident seals, and intrusion detection systems can help deter and detect physical tampering. From an expert perspective, it's crucial to understand that ATM jackpotting is not a new threat, but it continues to evolve. Cybersecurity professionals must stay informed about the latest attack vectors and ensure that their defenses are up to date. Collaboration with law enforcement and other financial institutions can also help in sharing threat intelligence and best practices. In conclusion, the arrest of the Florida men for ATM jackpotting serves as a reminder of the persistent threat posed by cyber-physical attacks. Financial institutions must remain vigilant and proactive in their security measures to protect against such sophisticated threats.
tinyurl.com
July 20, 2025 at 10:42 PM