Trends point to cyber criminals developing new malware that can steal cash directly from ATMs

Dubai: If 2014 was the year of the breach, then 2015 could to see high-stakes targeted cyber-attacks pinpointing banks and financial services institutions.
Cyber criminals are growing in confidence and they will develop new malware that can take cash directly from ATMs.
In addition to financial cybercrime, next year is also likely to bring even more privacy concerns, security worries about Apple devices and renewed fears about connected devices to prevent hackers using tools like network printers to penetrate corporate networks.
The proliferation of cyber tools and hacking knowledge is giving independent hacker and loosely connected groups an opportunity to participate in cyber-attacks against the region’s financial sector.
Kaspersky Lab’s experts recently discovered an attack in which an accountant’s computer was compromised and used to initiate a large transfer with a financial institution. It represented the emergence of a new trend: targeted attacks directly against banks.
Once attackers get into a bank’s network, they siphon enough information to allow them to steal money directly from the bank in several ways — Remotely commanding ATMs to dispose cash; performing SWIFT transfers from various customer accounts and manipulating online banking systems to perform transfers in the background
Alexander Gostev, chief security expert at global research and analysis team at Kaspersky Lab, said that most of the ATMs are still running on unsupported Windows XP and are incredibly vulnerable by default.
Windows XP presents a big opportunity to cybercriminals as they (hackers) will be able to uncover vulnerabilities without worry of Microsoft providing patches.
Windows XP’s sunny days are over on April 8, 2014, as Microsoft retired all its support and vital security patches to critical vulnerabilities for the hugely popular operating system.
Microsoft released Windows XP in 2001 and it normally supports an operating system for 10 years — five years of full support plus five years of extended support. For XP, Microsoft extended it for two more years because of its popularity. Updates for Microsoft Security Essentials, however, will be available until July 2015.
According to reports, about 95 per cent of the automated teller machines and about 60 per cent of the Point of sale (POS) systems are still running on XP globally.
“We expect to see further evolution of these ATM attacks with the use of targeted malicious techniques to gain access to the ‘brain’ of cash machine. The next stage will see attackers compromising the networks of banks and using that level of access to manipulate ATM machines in real time,” he said.
From Kaspersky Security Network statistics, more than 1,240 million attack notifications on Windows XP in 2013, which represent about 28 per cent of all attack notifications.
“Cybercriminals often reverse-engineer released patches to check which flaws that have been addressed and use that knowledge to target older, especially unsupported version of the software,” said Pradeesh VS, General Manager at ESET Middle East.
The sustained growth of the Middle East financial services industry depends on that industry’s ability to shore up its cyber defences and build protection on all fronts against attack.
Lutfi Zakhour, a vice-president at Booz Allen Mena, said that cyber security is a priority issue today for every stakeholder in the financial services industry — investor, consumer, regulatory, employees — all the way up to boards of directors.
That makes the “tomorrow” question — how will the threat evolve? In the aftermath of the Arab Spring, the provision of strong and secure financial services for businesses and consumers is necessary to the nurture of political and social security to Middle East residents.
Gostev expects to see another stage in the evolution of cybercriminal activity with the adoption of Advanced Persistent Threat (APT) tactics and techniques in financially motivated online criminal activity.
He expects criminals to leap at every opportunity to exploit payment systems. These fears can also be extended to the new Apple Pay, which uses NFC (Near Field Communications) to handle wireless consumer transactions. This is a ripe market for security research and we expect to the appearance of vulnerability warnings about weaknesses in Apple Pay, virtual wallets and other virtual payment systems.
In 2015, Gostev said there will surely be in-the-wild attacks against networked printers and other connected devices that can help an advanced attacker to maintain persistence and lateral movement within a corporate network.
“We expect to see IoT (internet of things) devices form part of an APT group’s arsenal, especially at high-value targets where connectivity is being introduced to the manufacturing and industrial processes.
On the consumer side, he said that IoT attacks will be limited to demonstrations of weaknesses in protocol implementations and the possibility of embedding advertising (adware/spyware?) into smart TV programming.
As security research teams continue to push for exposure of nation-state APT crews, Kaspersky Lab expects to see a shift in 2015 where the bigger, noisy APT groups splinter into smaller units, operating independently of each other. This in turn will result in a more widespread attack base, meaning more companies will be hit, as the smaller groups diversify their attacks.
At the same time, it means that bigger companies that were previously compromised by two or three major APT groups (eg. Comment Crew and Webky) will see “more diverse attacks, coming from more sources,” Gostev said.
“In a rapidly interconnected cyber world, the security of financial institutions is only as strong as its weakest link; therefore, a cohesive convergence of governments and the private sector is required in order to tackle the cybercrime challenge. The nature of attacks will evolve in terms of complexity and potential scalability placing predictive threat intelligence solutions and services at the Centre of security operations,” said Mahir Nayfeh, senior vice-president at Booz Allen Mena and oversees the firm’s technology and analytics team in the region.