Utilizing a zero-day bug, hackers steal cryptocurrency from Bitcoin ATMs

In order to steal bitcoin from users, hackers used General Bytes Bitcoin ATM servers’ zero-day vulnerability.

In order to steal bitcoin from users, hackers used General Bytes Bitcoin ATM servers’ zero-day vulnerability.

When users used the ATM to deposit or buy cryptocurrencies, the hackers would steal the money instead.

The company General Bytes produces Bitcoin ATMs that, depending on the model, let users buy or trade more than 40 different cryptocurrencies.

A remote Crypto Application Server (CAS) supervises the functioning of the Bitcoin ATMs, determines which cryptocurrencies are supported, and carries out cryptocurrency exchange buys and sells.

Hackers use CAS zero-day flaws

A General Bytes client contacted BleepingComputer yesterday to inform us that hackers were taking bitcoin from their ATMs.

Using a zero-day vulnerability in the organization’s Crypto Application Server, the assaults were carried out, according to a General Bytes security alert released on August 18th (CAS).

According to the General Bytes alert, “The attacker was able to remotely establish an admin user via CAS administrative interface via a URL call on the page that is used for the default installation on the server and generating the first administration user.”

Since version 20201208, CAS software has had this vulnerability.

Threat actors, according to General Bytes, combed the internet for unprotected servers using TCP ports 7777 or 443, including those running General Bytes’ own cloud service and servers located at Digital Ocean.

The threat actors then used the flaw to modify the CAS’s ‘buy’ and sell crypto settings and ‘invalid payment address’ to utilize a hacker’s cryptocurrency wallet as well as install a default admin account named ‘gb’.

Any bitcoin that CAS received after the threat actors changed these parameters was instead sent to the hackers.

According to the security alert, “Two-way ATMs started to transmit funds to the attacker’s wallet when users sent coins to ATM.”

Customers of General Bytes are being advised not to use their Bitcoin ATMs until two server patch releases—20220531.38 and 20220725.22—have been implemented to their servers.

They also provide a checklist of procedures to carry out on the equipment before it is placed back into use.

It is crucial to keep in mind that if the servers were firewalled to only permit connections from trustworthy IP addresses, the threat actors would not have been able to carry out these assaults.

It is crucial to set up firewalls so that they only permit access to the Crypto Application Server from a reliable IP address, such as the location of the ATM or the customer’s offices.

There are now 18 General Bytes Crypto Application Servers still open to the Internet, with the bulk being situated in Canada, according to data given by BinaryEdge.

How many servers were compromised using this flaw, and how much bitcoin was taken, is unknown.

General Bytes was contacted by BleepingComputer yesterday with more inquiries on the assault, but no comment was given.