• ENEN
    • IT IT
    • ES ES
PARTNER LOGIN
  • ENEN
    • IT IT
    • ES ES

Auriga

  • COMPANY

    • About Us

    • Auriga History

    • Group

    • Our Values

    • Our Network

      • Partnerships

      • Certifications

      • Suppliers

    • CSR (ethical code)

      • CSR – Corporate Social Responsibility

  • BANKING

    • Overview

    • Needs

      • Channel Integration

      • Monitoring network

      • Marketing & Customer Relations

      • Accessibility of banking service

      • Corporate Banking

      • Banking Data Analysis

      • Branch of the Future

      • ATM network security

    • Products and Solutions

      • Shared Services

        • WinWebServer Architecture

        • Proactive Network Monitoring

        • One to One Marketing

      • ATM / Kiosks

        • WWS ATM

      • Internet / PC

        • WWS Digital Banking

      • Mobile Banking and Payments

        • WWS Mobile

      • Electronic payments

        • MyBank

      • Bank Marketing & Digital Signage

        • WWS One to One OMNIA

        • WWS Signage

        • WWS Perfect

        • WWS RSS Feed

        • WWS Simply Feed

      • Network Monitoring & Fraud Management

        • WWS Proactive Monitoring OMNIA

        • WWS Fraud Management System

        • WWS Simply Check

      • Call Centre

        • WWS Help Desk

      • Cash Handling

        • WWS Cash Handling

        • WWS Cash Management

      • Digital Invoicing and Document Management

        • WWS e-Invoicing

      • Branch

        • WWS Fill4Me and Bank4Me

        • WWS Greæter

        • WWS Customer Management

      • Business Analytics

        • WWS Business Analytics Management

        • WWS Asset Management

      • Cyber Security Platform

        • Lookwise Device Manager

  • NEWS & MEDIA

    • News

    • Press Release

    • Press Review

    • Blog

    • Videos

    • Infographics

  • RESOURCES

    • White Papers

    • Customer stories

    • Research

    • Brochures

  • CONTACT

    • Contact us

  • CAREERS

    • Work for Us

    • Online application

    • Job vacancies

Press Release

  • Home
  • News & Media
  • Press Release
  • How Banks Can Shut Down FASTCash, the New North Korean ATM Jackpotting Attack
Cybersecurity-ATM-FastCash-Press-Release-ENG

How Banks Can Shut Down FASTCash, the New North Korean ATM Jackpotting Attack

29 October 2024 / Press Release

ATM jackpotting continues to be a threat to banks. This month a new report reveals that North Korean hackers are using a new Linux variant of the FASTCash malware to trigger unauthorized cash withdrawals.

Auriga, which provides multivendor management and specialist cybersecurity for bank devices including ATMs and ASSTs, believe banks can protect themselves against this renewed threat.

Néstor Santolaya Bea, Auriga’s banking cybersecurity expert says:

“Firstly, banks need to know that FASTCash is not ATM but server-side malware, and the new variant attacks now the internal Linux switches of the network. It takes over the switches so that a reply message of “unauthorized transaction” is converted to an authorized transaction for specific primary account numbers (PANs). The attack is enabled by how FASTCash exploits the lack of end-to-end data encryption between the server and the ATM where the jackpot happens.

The good news is banks and ATM operators can prevent these attacks by implementing security protocols such as TLS in communications between the ATM operating software like Auriga WWS and the central systems of the banks. This ensures that the data transmitted is encrypted with secure algorithms and unreadable by unauthorized users. As a result, hackers cannot intercept the exchanged data and modify it fraudulently.

It is also wise to switch on security mechanisms to guarantee the integrity of messages such as the MAC (Message Authentication Code) on the ISO8583 message fields. In this way, malware would not be able to alter the messages without being detected. The MAC, generated with symmetric keys, would be used to verify the integrity of the messages exchanged between the ATM operating software and the central banking systems.”

If you want to learn more about this topic do not hesitate to contact us and we would be very happy to set up a call with him to discuss current and future ATM hacking trends and exploits.

Download the press release

For information about Auriga’s PR activities and to receive our press kit:
Contact the Communication Department

    
  • Tweet
  • News
  • Press Release
  • Press Review
  • Blog
  • Videos
  • Infographics

DO YOU WANT INSIGHTS FROM THE WORLD’S BANKING INDUSTRY?

JOIN THE AURIGA COMMUNITY TO BE ALWAYS UPDATED ON:

News on software solutions

Invitations to industry events

Customer stories

Reports

Market research

...and much more!

LET'S CONNECT
CONTACT

HEADQUARTER - BARI
Via Don Luigi Guanella, 17
70124 Bari - Italy

TEL: +39.080.5692111

info@aurigaspa.com

Milan office
Rome office
Brussels office
London office
Madrid office
Mexico City office

BUSINESS CONTACTS
Niccolo Garzelli - Auriga - Footer

Niccolò Garzelli Milan office
niccolo.garzelli@aurigaspa.com

MARK ALDRED London office
mark.aldred@aurigaspa.com

brendan-thorpe-contacts

BRENDAN THORPE London office
brendan.thorpe@aurigaspa.com

Stefano Cipollone Milan office
stefano.cipollone@aurigaspa.com

MARTIN ESPINELMexico City office
martin.espinel@aurigaspa.com

lukasz-feluch

ŁUKASZ FELUCHVarsaw office
lukasz.feluch@aurigaspa.com

RUDY DE WOLFBrussels office
rudolf.dewolf@aurigaspa.com

angel arenillas

ÁNGEL ARENILLAS YUSTEMadrid office
angel.arenillas@aurigaspa.com

Kelum-Dissanayake-Auriga-Footer

Kelum Dissanayakekelum.dissanayake@aurigaspa.com

EXPLORE
  • About Us
  • WinWebServer
  • Blog
  • White Papers
  • Research
LATEST NEWS
  • AURIGA-A-FUTURE-BANKS-SUMMIT-2025-DI-DUBAI-News

    Auriga and ACI Worldwide to Share Omnichannel Banking Insights at Future Banks Summit 2025

    10/06/2025
  • Example of phishing email used in a social engineering cyber attack

    From Hoax to Hack: When Panic Is the Payload

    26/05/2025
  • Hybrid-Branch-Digital-and-Physical-Blog-ENG-Auriga

    The Hybrid Branch: Blending Digital and Physical Banking

    14/04/2025

Connect with us

SUBSCRIBE TO THE NEWSLETTER

Join the Auriga community

Let's connect

Auriga Spa - Copyright © 2025 - All rights reserved | Legal Notice | Privacy Policy | Whistleblowing Policy | Social Media Policy
P.I. 05566820725 - Capital € 1.196.055 i.v. - R.E.A. 426675

TOP
Gestisci Consenso

We, and third party websites you may interact with via our site, use cookies to collect site usage data and improve your experience, this includes permanent and profiling cookies. By clicking ‘Accept’ you agree to allow cookies, however you can disable this through your browser settings at anytime. If you opt to totally or partial disable cookies, this might compromise some features on the website. For more information on our cookie policy, go to the Legal Notice page.

Functional Always active
L'archiviazione tecnica o l'accesso sono strettamente necessari al fine legittimo di consentire l'uso di un servizio specifico esplicitamente richiesto dall'abbonato o dall'utente, o al solo scopo di effettuare la trasmissione di una comunicazione su una rete di comunicazione elettronica.
Preferenze
L'archiviazione tecnica o l'accesso sono necessari per lo scopo legittimo di memorizzare le preferenze che non sono richieste dall'abbonato o dall'utente.
Statistiche
L'archiviazione tecnica o l'accesso che viene utilizzato esclusivamente per scopi statistici. L'archiviazione tecnica o l'accesso che viene utilizzato esclusivamente per scopi statistici anonimi. Senza un mandato di comparizione, una conformità volontaria da parte del vostro Fornitore di Servizi Internet, o ulteriori registrazioni da parte di terzi, le informazioni memorizzate o recuperate per questo scopo da sole non possono di solito essere utilizzate per l'identificazione.
Marketing
L'archiviazione tecnica o l'accesso sono necessari per creare profili di utenti per inviare pubblicità, o per tracciare l'utente su un sito web o su diversi siti web per scopi di marketing simili.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}