Bonum Certa Men Certa

"FASTCash" is Not a "Linux" Thing, It Was Merely Extended to Also Have a Variant for Already-Compromised Ubuntu 22.04

posted by Roy Schestowitz on Oct 18, 2024

Johnny Cash museum sign at Nashville, Tennessee

SOME days ago we spotted and took note of this article from a Microsoft-connected site. We thought it was safe to ignore because it was just one piece, it seems like overhyped (or dramatised, anti-Linux) "reporting" that wrongly attributes to Linux something that can merely run on some old version of it, and we didn't want to give it undeserved attention. A quick rebuttal in editorial comments is typically enough. But hours later we saw lots of this in "news" sites, typically citing the Microsoft-connected site, e.g. [1-7].

An associate explained that "it is part of a trend of disparaging "Linux" and OSS in general. As mentioned earlier [previous articles, too] it is very likely to accompany the lobbying taking place at the moment in DC."

"Same for the push for 'passkeys' and other proprietary gimmicks, all of which increase surveillance and reduce options -- especially FOSS options. Andy wrote about this last month."

From what we can gather, all the articles below basically say that there is some bit of malicious software and it can be executed in several operating systems. Recently it was also seen executed on Ubuntu 22.04, but that does not mean that this software can just break into Ubuntu 22.04. It's most likely the case that some weak password, misconfiguration or badly out-of-date software lets someone get in, then install the malware.

Is that the fault of Linux? No. But notice these daunting headlines.

Related/contextual items from the news:

  1. North Korean hackers utilizing Linux tool to hack ATMs

    North Korean hackers are using a new tool to steal cash from ATMs: a Linux variant of FASTCash malware. This malware has been used in some form since 2016 and has stolen tens of millions of dollars in cash through unauthorized withdrawals at ATMs, according to a report by Bleeping Computer.

  2. A new Linux variant of FASTCash malware targets financial systems

    North Korea-linked actors deploy a new Linux variant of FASTCash malware to target financial systems, researcher HaxRob revealed.

    The cybersecurity researcher HaxRob analyzed a new variant of the FASTCash “payment switch” malware which targets Linux systems. The variant discovered by the researcher was previously unknown and targets Ubuntu 22.04 LTS distributions.

  3. North Korean hackers use newly discovered Linux malware to raid ATMs

    In the beginning, North Korean hackers compromised the banking infrastructure running AIX, IBM’s proprietary version of Unix. Next, they hacked infrastructure running Windows. Now, the state-backed bank robbers have expanded their repertoire to include Linux.

    The malware, tracked under the name FASTCash, is a remote access tool that gets installed on payment switches inside compromised networks that handle payment card transactions. The US Cybersecurity and Infrastructure Security Agency first warned of FASTCash in 2018 in an advisory that said the malware was infecting AIX-powered switches inside retail payment networks. In 2020, the agency updated its guidance to report FASTCash was now infecting switches running Windows as well. Besides embracing Windows, FASTCash had also expanded its net to include not just switches for retail payments but those handled by regional interbank payment processors as well.

  4. North Korea Hackers Get Cash Fast in Linux Cyber Heists

    North Korean threat actors are using a Linux variant from a malware family known as "FASTCash" to conduct a financially motivated cyber campaign.

  5. A new Linux-based FASTCash malware steals money from ATMs

    The new FASTCash malware has a new variant for Linux that helps North Korean hackers breach ATMs and execute unauthorised money withdrawals.

    According to reports, previous malware versions could only target IBM and Windows computers, but a new variant has emerged that can target the Ubuntu 22.04 LTS distributions.

  6. North Korean Hackers Deploy Linux FASTCash Malware for ATM Cashouts

    North Korean hackers target Linux-based payment switches with new FASTCash malware, enabling ATM cashouts. Secure your financial infrastructure and protect against these sophisticated attacks with expert cybersecurity solutions.

  7. FASTCash GNU/Linux Malware: A New Cybercrime Menace Targeting Payment Switch Systems
    As malware threats evolve to increasingly target GNU/Linux systems, admins and organizations must stay up-to-date on the latest GNU/Linux malware variants and strategies for detecting and preventing attacks. Security researcher HaxRob recently discovered a new GNU/Linux variant of the FASTCash malware , which targets payment switches to enable unauthorized ATM withdrawals.

Other Recent Techrights' Posts

The Slop ('Linux') Foundation Celebrates 35 'Linux' Years a Week After GNU/Linux Turns 43
they'll keep on trying to change history
FOSSY (SFC) Platforming GAFAM, Sells Endorsement
Houston, we have a problem here
 
Even ZDNet Accepts That "Market Share" of GNU/Linux May Have Doubled on Desktops and Laptops
GNU/Linux is definitely growing, and quite quickly in fact
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, August 11, 2026
IRC logs for Tuesday, August 11, 2026
Microsoft Layoffs and Shutdowns Continue This August, Morale Low, Employees Set Up Giant Inflatable Rat to Protest Against CEO
nothing demonstrates their anger better than what they did to the CEO
Gemini Links 12/08/2026: Sophomore Slump, Mandatory Phone Addiction, and Vintage Web Game Gallery
Links for the day
Summer Layoffs and 'Redundancies' (Cost-Cutting) at Microsoft and IBM
IBM is merely buying its revenue - an unsustainable strategy that aims to hide the company's rapid decline
Links 11/08/2026: Tensions South of China and Stingy "YouTube Doubles the Eligibility Requirements" (to Get Paid)
Links for the day
The Independent (UK) Today: "Independent candidate Daniel Pocock is concerned about media issues."
Let's see what results say around Friday
Gemini Links 11/08/2026: Stargate, Stargazer, Air-gapped Environments, and SystemVerilog Simulator
Links for the day
Keumars Afifi-Sabet Produces Useful, Informative Coverage Regarding Privacy
And it's good for Richard Stallman
Confirmed: Microsoft Layoffs in August 2026, Entire Operations Shut Down Too
Microsoft is just bleeding
Paying With Cash in 2026
Cash isn't going away. Not any time soon.
Blocking Tor Is Not a Solution, It's Paranoia
Tor is not a crime
Oligarchs and Their Footsoldiers Are Most Enthusiastically Loud About the Things They're Attacking
Like "Microsoft loves Linux"
Not Allowing Misogyny and Misogynists to Run the World
We stand with (and for) equality, justice, and freedom
"SPONSORED EXPLAINER" at The Register MS is Just More SPAM "Sponsored by HPE."
This is a great example of crap 'journalism'
IBM Won't Hire (or Hardly Hire) This Year
IBM is bluffing with buzzwords while shrinking out of existence and reducing salaries
SLAPP Censorship - Part 146 Out of 200: An Industry of Plagiarism, 'Normalised'
they pursue personal enrichment by stealing from Free software developers
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, August 10, 2026
IRC logs for Monday, August 10, 2026
5.1k Capsules Known to Lupa, Gemini Protocol Crawler
If no limits (e.g. 10k max per capsule) were imposed on crawling, there would likely be millions of pages in the database
Gemini Links 11/08/2026: Waking Up Earlier, Whining About LLMs as Destructive Plagiarism
Links for the day
Links 11/08/2026: "The Enemy Is the Platform" and 'Vibe' 'Coding' Shown to be Little But Plagiarism
Links for the day
IBM's Age Discrimination Leads Workers to Contemplate Suicide While the CEO Becomes Billionaire for Lying to the Press and Faking Performance (Fraudulent Accounting)
IBM avoids issuing WARM notices
If Your Software Project Welcomes Bots, Then All You'll Have Left at the End Is Bots (Same for Sites Which Permit LLM Slop; They End up as Slopfarms and No Human Wants to Contribute Anymore)
A "slippery slop."
Clownflare Affirms Disturbing Trend of Web Monoculture (Which Extents to Clownflare Itself)
Clownflare itself is another layer of the same problem
The Open Web Is Not Coming Back
the open Web going out of control
Tell Me Something I Don't Know
Those who have a stake in the secrecy would do anything to maintain secrecy
Gemini Links 10/08/2026: Recollections and Washing Machine That Only Last a Few Years
Links for the day
Claims of Mass Layoffs at IBM (in Finance)
IBM tries hard to maintain an illusion of normality - to the point of viciously censoring critics and whistleblowers.
The Slop Bubble (Pyramid Scheme) is Becoming Bigger and Everyone Should be Terrified (Its Implosion Will Cause More Damage)
there's no plan for a turnaround
Microsoft and Apple Lose Ground to GNU/Linux in the United States
This contributes a lot to the international curve
Escaping Ads
When users do not want ads, then no ads should show up, period
For Second Year in a Row Software Freedom Conservancy (SFC) Loses Money (Over $3,000,000 Lost in 2 Years), Bradley M Kuhn Steps Down as Treasurer
lost almost $600,000 last year
Microsoft/GAFAM Operating at a Loss
Microsoft has financial problems
Nigel Farage crisis: Taylor Swift & Jeffrey Epstein both shunned cryptocurrency bosses
Reprinted with permission from Daniel Pocock
statCounter Now Sees GNU/Linux "Market Share Worldwide" at 9.21%, Soon 10%
If this data is more or less accurate, it's time for panic at Microsoft
Rumours of Impending Mass Layoffs in IBM's Yorktown Office, Impacting the LLM (Slop) Staff
Bubbles never last forever, hence their name
Links 10/08/2026: "Long COVID Linked to Lasting Damage in The Brain's Dopamine System", Microsoft’s Weather App Uses Over 1,000 Megabytes of RAM
Links for the day
Software Freedom Conservancy (SFC) Does Not Support Women, It Imitates Authentic Organisations, Embraces Misogynists, Then Projects
They try to monetise for personal gain at the expense of unpaid volunteers
When You're Evil and You're Publicly Attacking Something, That Something Will Become More Popular
when an oppressor becomes openly oppressive and does anything to squash/censor critics, the outcome will typically be detrimental to the oppressor
Links 10/08/2026: "Against Oligarch" and "The Invisible Women"
Links for the day
Social Control Media Deathwatch: After Nearly a Million Posts Sent EchoFeed Shuts Down
EchoFeed is hardly unique
When the LLM Chatbots Industry (Trillions in the Red) Quits Paying the Media for FOMO
fear of missing out, or FOMO for short
Microsoft Killing Morale
branding the process “inhumane” and “demoralizing”
Google's "AI Overview" as Proprietary Censorship Engine and Gatekeeper
People do not choose to use this, Google is just shoving that in people's faces, encouraging laziness and misinformation
SLAPP Censorship - Part 145 Out of 200: They Tried Hard to Hide the Fact Their Client Had Been Sued, Twice Even
A month ago Brett Wilson LLP tried to take my wife "to the side" (in effect isolated) to make her an offer
statCounter: GNU/Linux Up to 8.95% Globally
So the estimates are being "corrected" upwards, not downwards
Explaining How Someone Attempted to Cancel RMS This Year (and Failed)
The process itself involved debunking some falsehoods
Microsoft's "XBOX Ranks Last", IBM is Headed for Extinction
If Microsoft cannot dominate its own "home turf", what prospects are there elsewhere?
DebConf6 fight denied by Google artificial intelligence
Reprinted with permission from Daniel Pocock
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, August 09, 2026
IRC logs for Sunday, August 09, 2026
Gemini Links 10/08/2026: A Mild Monday, Sleepy Saturday, OUYA, and Moving to GNU/Linux
Links for the day