New North Korean malware targeting ATMs spotted in India

DDE_Server

Level 22
Thread author
Verified
Top Poster
Well-known
Sep 5, 2017
1,173
Another version of the same malware, but with RAT-like features, spotted targeting Indian research centers.

5bb63f2a60b20556c4146282-1280x7201oct042018203108poster.jpg






SEE ALSO
North Korean hackers have developed and have been observed using a new malware strain that can be planted on ATM systems and used to record and steal data from payment cards inserted into a machine.
Named ATMDtrack, this new malware has been spotted on the networks of Indian banks since late summer 2018, Kaspersky experts said in a report published today.
Newer attacks have also targeted Indian research centers with a more potent and expanded version of the same malware, named DTrack, which focuses on spying and data theft, rather than financial crime, and comes with features normally found in remote access trojan (RAT).
LINKS TO NORTH KOREA'S BIGGEST STATE HACKER GROUP
Kaspersky researchers said both malware strains, which they collectively track as the DTrack family, had many similarities with malware used in "Operation DarkSeoul," which is a series of attacks aimed against South Korean targets in 2013.
Those attacks have been attributed to the Lazarus Group, a well-known cyber-espionage outfit operating at the behest of the North Korean government.

The Lazarus Group is one of the three North Korean hacker groups that have been sanctioned by the US Treasury ten days ago for orchestrating cyber-attacks on banks, ATM networks, gambling sites, online casinos, and cryptocurrency exchanges to steal money from legitimate businesses and raise funds for the country's weapons and missile programs.
In other words, the discovery of the ATMDTrack malware strain comes to support and justify the US Treasury's decision to sanction any entities associated with this group, fitting right into Lazarus' normal mode of operation.
DTRACK MALWARE SPOTTED AS RECENTLY AS THIS MONTH


Eliminate spyware challenges with these 10 tips

One of the biggest problems you face is supporting desktops today is the challenge presented by spyware. Here are 10 tips you can use to fight spyware.
Furthermore, DTrack appears to be one of the Lazarus Group's most recent creations. First deployed in the late summer of 2018, Kaspersky said the most recent samples have been seen active as recent as this month, September 2019.
Recent DTrack samples can perform the following operations:
  • Keylogging,
  • Retrieve browser history,
  • Gather host IP addresses, information about available networks and active connections,
  • List running processes,
  • List files on all available disk volumes.
Based on currently available information, it is unclear if DTrack evolved from ATMDTrack, or if ATMDTrack was developed from the main DTrack strain when North Korean hackers managed to breach Indian backs last year and needed a specialized tool to target ATMs.
 
9

93803123

If this is happening in India, and the article is about what is happening in India, then why is there a white guy using a U.S. ATM in the photo above ?
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top