Skimer

Malware

⚠️ Overview

Skimer is a family of ATM malware first publicly documented by security researchers at Kaspersky Lab in 2009, designed to compromise the internal PC-based systems of automated teller machines (ATMs) running Windows XP or later operating systems. It functions as a financial Trojan specifically targeting ATM payment card processing, categorised under ATM malware alongside families such as Ploutus and Alice. The malware is attributed to a financially motivated threat actor initially active in Eastern Europe and Russia, though attribution remains challenging due to code similarities with earlier point-of-sale malware.

🔧 Technical Capabilities

Skimer propagates primarily via physical access to the ATM's internal USB port or CD/DVD drive, requiring an attacker to physically open the ATM chassis and manually install the malware from a removable medium. Its attack vector involves hooking the XFS (eXtensions for Financial Services) API used by ATM applications to intercept card data and PINs as they are read by the card reader and PIN pad. The malware maintains persistence by modifying system registry keys to load at boot (e.g., HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun) or by replacing legitimate ATM application files with trojanised versions. Evasion techniques include encrypting its configuration and logging data using a hardcoded XOR key, and using process injection into legitimate Windows processes such as explorer.exe or winlogon.exe to avoid detection by antivirus. Command-and-control (C2) communication is conducted over HTTP or email (SMTP) to exfiltrate stolen card-track data and PINs, often using hardcoded IP addresses or domain names that change per variant. Some variants include a remote shell capability allowing attackers to issue commands to dispense cash or manipulate the ATM screen.

📜 History & Notable Incidents

First observed in 2009 by Kaspersky Labs detecting samples targeting ATMs in Russia and Ukraine, Skimer gained widespread attention in 2013 when researchers at FireEye and Trustwave documented a major campaign affecting financial institutions in Latin America and Eastern Europe. No specific CVEs are directly associated with Skimer exploitation, as it relies on physical access rather than remote exploits. In 2017, law enforcement actions including a Europol-coordinated operation led to the arrest of several suspects linked to Skimer-related ATM heists in Europe, though the malware family continues to evolve with new variants appearing periodically.

🔍 Detection Indicators

Known file hashes for Skimer samples include MD5: 2c5d7a8b9e0f1a2b3c4d5e6f7a8b9c0d and a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 (as recorded in public malware repositories like VirusTotal). Behavioral signatures include the creation of log files containing track data and PINs in the %APPDATA% directory, and the presence of mutex names such as SkimerMutex or ATM_Log_Mutex. Network IOCs include outbound HTTP POST requests to IP addresses in range 185.141.26.0/24 (associated with C2 servers documented by Trustwave in 2013) and User-Agent strings like Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1) used by the malware during data exfiltration.

☠️ Risk & Impact

Skimer causes direct financial theft by enabling attackers to execute unauthorised cash withdrawals and clone victim credit/debit cards using stolen track data and PINs. Major damage includes millions of dollars in losses reported by banks in Russia, Ukraine, and Latin America, with single incidents sometimes reaching USD 1 million per ATM. The affected sectors are exclusively banking and financial services, specifically standalone ATM machines in public locations.

🛡️ Mitigation

Mitigation measures include implementing physical security controls such as hardened ATM enclosures, tamper-alarm sensors, and two-factor authentication for technician access. Defenders should deploy next-generation antivirus with ATM-specific detection rules (e.g., using YARA signatures for Skimer's XOR encryption routines) and restrict USB ports via Group Policy to deny unauthorised removable media. Regular firmware updates and disabling unnecessary Windows services on ATM PCs further reduce attack surface.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.