North Korean hackers use newly discovered Linux malware to raid ATMs

The malware FASTCash tampers with switch messages received from card issuers during a financial transaction, changing denials into approvals. The systems targeted often have misconfigurations preventing message authentication mechanisms from detecting tampered messages as fraudulent. The group responsible, BeagleBoyz, is a subset of North Korean-backed group HiddenCobra, which has attempted to steal nearly $2 billion since 2015 by disrupting critical banking systems.

