Reports are emerging of the Logical attack hitting ATM machine in Pakistan recently where the attacker used external device to inject malicious code in the ATM software. It is observed from the initial analysis that the attacker physically opened the ATM machine and injected the malicious code via USB port by logging into Windows “quoted in NCR advisory”. While more details emerge, NCR has recommended banks to take certain actions to avoid any further losses given in the remediation section.
Changing passwords for all ATMs to avoid attackers from logging into the machine.
If you are using EPO Solidcore, change the password of Solidcore via EPO server and ensure the machines are all in locked down mode. This will stop the attacker from injecting the malicious code in the ATM via windows.
Securing the BIOS via password to stop the attacker to BOOT the ATM machine and inject malicious code in the hard drive.