Kaspersky Lab Identified the new ATM-hacking Malware-kit Designed for non-professional Criminals
By FF Newsroom · 18 October 2017

Kaspersky Lab researchers have discovered a malware targeting ATMs, which was being openly sold on the DarkNet market. Cutlet Maker consists of three components and enables ATM jackpotting if the attacker is able to gain physical access to the machine. A toolset potentially allowing criminals to steal millions was on sale for just £3,788 and came equipped with a step-by-step user guide.
ATMs continue to be lucrative targets for fraudsters, who use various methods to extract maximum profit. While some rely on physically destructive methods through the use of metal cutting tools, others choose malware infection, enabling them to manipulate cash dispensers from the inside. Although malicious tools for hacking ATMs have been known for many years, the latest discovery shows that malware creators are investing more and more resources into making their “products” available for criminals who are not very familiar with computer science.
Earlier this year, a Kaspersky Lab partner provided one of our researchers with a previously unknown malicious sample presumably made to infect PCs running inside ATMs. Researchers were curious to see if this malware or something related to it was available to purchase on underground forums. A subsequent search for the unique artifacts of the malware was successful: an advertising offer describing a strain of ATM malware on a popular DarkNet spot – AlphaBay - matched the search query and revealed that the initial sample belonged to a whole commercial malware-kit created to jackpot ATMs. A public post by the malware seller, found by researchers, contained not only the description of the malware and instructions on how to get it, but also provided a detailed step-by-step guide on how to use the malware-kit in attacks, with instructions and video tutorials.
According to the research, the malware toolkit consists of three elements:
- Cutlet Maker software, which serves as the main module responsible for communicating with the ATM’s dispenser.
- c0decalc program, designed to generate a password in order to run the Cutlet Maker application and protect it from unauthorised use.
- Stimulator application, which saves time for criminals by identifying the current status of ATM cash cassettes. By installing this app, an intruder receives exact information on the currency, value and number of notes in each cassette, so can then choose the one containing the largest amount, instead of blindly withdrawing cash one by one.
- Implement strict default-deny policies preventing any unauthorised software from running on the ATM.
- Enable device control mechanisms to restrict the connection of any unauthorised devices to the ATM.
- Use a tailored security solution to protect your ATMs from attacks from the likes of the Cutlet Maker malware.