New FASTCash malware Linux variant helps steal money from ATMs

Teilen:

North Korean hackers are using a new Linux variant of the FASTCash malware to infect the payment switch systems of financial institutions and perform unauthorized cash withdrawals.

Previous variants of FASTCash targeted Windows and IBM AIX (Unix) systems, but a new report by security researcher HaxRob reveals a previously undetected Linux version that targets Ubuntu 22.04 LTS distributions.

Money-stealing history

CISA first warned about the FASTCash ATM cash-out scheme in December 2018, attributing the activity to the state-backed North Korean hacking group known as ‘Hidden Cobra.’

According to the agency’s investigations, the threat actors have been using FASTCash in operations since at least 2016, stealing tens of millions of dollars per incident in simultaneous ATM withdrawal attacks in 30 countries or more.

In 2020, the U.S. Cyber Command highlighted the threat once again, linking the revived FASTCash 2.0 activity to APT38 (Lazarus).

A year later, indictments were announced for three North Koreans allegedly involved in these schemes, responsible for the theft of over $1.3 billion from financial institutes worldwide.

Cashing out from Linux

The newest variant spotted by HaxRob was first submitted to VirusTotal in June 2023 and features extensive operational similarities to previous Windows and AIX variants.

It comes in the form of a shared library that is injected into a running process on a payment switch server with the help of the ‘ptrace’ system call, hooking it into network functions.

These switches are intermediaries handling the communication between ATMs/PoS terminals and the bank’s central systems, routing transaction requests and responses.

The malware intercepts and manipulates ISO8583 transaction messages used in the financial industry for debit and credit card processing.

Specifically, the malware targets messages that concern declines of the transactions due to insufficient funds in the cardholder’s account and replaces the “decline” response with “approve.”

FASTCash operational overview
FASTCash operational overview
Source: doubleagent.net

The manipulated message also contains a random amount of money between 12,000 and 30,000 Turkish Lira ($350 – $875) to authorize the requested transaction.

Once the manipulated message is sent back to the bank’s central systems containing the approval codes (DE38, DE39) and the amount (DE54), the bank approves the transaction, and a money mule acting on behalf of the hackers withdraws the cash from an ATM.

As of its discovery, the Linux variant of FASTCash had no detections on VirusTotal, meaning it could evade most standard security tools, allowing the threat actors to perform transactions undeterred.

HaxRob also reports that a new Windows version was submitted on VT in September 2024, indicating that the hackers are actively working on evolving all the pieces of their toolset.

Bill Toulas

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
1:52 pm, Juni 12, 2025
Wetter-Symbol 23°C
L: 22° | H: 23°
overcast clouds
Luftfeuchtigkeit: 63 %
Druck: 1011 mb
Wind: 11 mph E
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:17 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
22° | 23°°C 0.76 mm 76% 10 mph 75 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
16° | 28°°C 1 mm 100% 9 mph 93 % 1020 mb 0 mm/h
Sa. Juni 14 10:00 pm
Wetter-Symbol
16° | 23°°C 0.8 mm 80% 13 mph 98 % 1020 mb 0 mm/h
So. Juni 15 10:00 pm
Wetter-Symbol
13° | 21°°C 0.2 mm 20% 10 mph 85 % 1025 mb 0 mm/h
Mo. Juni 16 10:00 pm
Wetter-Symbol
13° | 24°°C 0 mm 0% 7 mph 86 % 1028 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
23° | 24°°C 0.76 mm 76% 10 mph 61 % 1011 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
24° | 25°°C 0 mm 0% 9 mph 61 % 1012 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
19° | 19°°C 0 mm 0% 4 mph 75 % 1015 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 3 mph 80 % 1016 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 3 mph 84 % 1017 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 7 mph 79 % 1018 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
22° | 22°°C 0 mm 0% 7 mph 58 % 1020 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
26° | 26°°C 0 mm 0% 6 mph 47 % 1019 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,552.45
-2.14%
Ethereum(ETH)
€2,365.91
-2.22%
Fesseln(USDT)
€0.86
0.01%
XRP(XRP)
€1.92
-4.00%
Solana(SOL)
€137.25
-4.67%
USDC(USDC)
€0.86
0.01%
Dogecoin(DOGE)
€0.162674
-6.22%
Shiba Inu(SHIB)
€0.000011
-5.17%
Pepe(PEPE)
€0.000010
-5.37%
Peanut das Eichhörnchen(PNUT)
€0.236997
-5.02%
Nach oben scrollen