FiXS Malware Targets ATM Units in Latin America

Scammers Abuse Zelle to Steal Money

Metabase Q, a cybersecurity company, has discovered a new malware family that targets ATMs in Latin America, named FiXS. This threat, which contains Russian metadata, is currently attacking banks in Mexico, but it is not vendor-specific and can work on any ATM that supports CEN XFS. FiXS is similar to Ploutus ATM malware in that it requires an external keyboard and is probably being deployed by cybercriminals who have physical access to ATMs.

Metabase Q reports that FiXS hides within a seemingly harmless program, instructs the infected ATM to dispense money half an hour after the last reboot, and waits for the cassettes to be loaded first. The malware is embedded in a dropper that decodes the malware and stores it in the system's temp directory. FiXS is then executed.

The malware can operate on any Windows-based ATM with only minor modifications, thanks to the CEN XFS APIs. FiXS runs in an infinite loop, seeking the correct keyboard input to display a window, show cash unit information, close the session and terminate the process, or dispense money. Unlike other more sophisticated ATM malware, such as Ploutus, FiXS has a limited interface and can only display the numbers of bills.

Metabase Q suggests that since the malware instructs the cash terminal to dispense money 30 minutes after the last reboot, it is likely that the cash is retrieved by mules soon after the malware's installation.

How Can Malware Impact Hardware Like ATM Units?

Malware can significantly impact the hardware of ATM units in several ways. Once installed, malware can manipulate the firmware and software of an ATM, allowing cybercriminals to execute commands remotely, such as dispensing cash or stealing card information. Malware can also alter an ATM's settings, making it vulnerable to future attacks.

Furthermore, malware can cause physical damage to an ATM's hardware, which can disrupt the machine's functionality, rendering it inoperable. Additionally, malware can cause the system to crash or freeze, which could lead to a temporary or permanent outage, impacting the availability of the ATM and potentially causing significant financial losses.

In summary, malware can have a severe impact on ATM hardware, resulting in compromised security, theft, system failures, and financial losses. It is essential to implement comprehensive security measures and keep hardware up-to-date to prevent malware attacks on ATM units.

March 9, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.