Blog | G5 Cyber Security

Kaspersky spotted ATMii, a new strain of ATM malware

ATMii is a new strain of ATM malware dubbed ATMii that could be used to empty an ATM. Cyber criminals need a direct access to a target ATM, either physically or over the network, to install the malicious code. The malicious code works for Windows XP and later that are the OSs most ATMs run. The injected module attempts to find the ATMs CASH_UNIT service id to and stores the result. The available commands allow dispensing a desired amount of cash, retrieve information about ATM cash cassettes, and completely remove the C:ATMcini file from the ATM.”]

Source: https://securityaffairs.co/wordpress/64196/malware/atmii-atm-malware.html

Exit mobile version