Threat reportAPTTL-2026-0564

UNC2891 Bank Heist — CAKETAP Solaris Rootkit and 4G Raspberry Pi Physical Implant Targeting ATM Switching Network

criticalMONITORING

UNC2891 Bank Heist (TL-2026-0564), also tracked as UNC2891 Bank Heist, is a critical-severity advanced persistent threat campaign, first published 2026-05-22. It is attributed to UNC2891 with high confidence, affects Oracle Solaris, maps to 27 MITRE ATT&CK techniques (T1003.008, T1005, T1014), and is covered by 9 detection rules and 24 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
27MITRE ATT&CK
Actors
1UNC2891
Detection rules
9SPL · KQL · Sigma
IOCs
24Indicators of compromise

Key facts for TL-2026-0564

Threat ID
TL-2026-0564
Also known as
UNC2891 Bank Heist, CAKETAP ATM Heist, Asia-Pacific Bank Pi Implant
Severity
CRITICAL
Status
MONITORING
Category
APT
First published
Last reviewed
Attribution
UNC2891
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
financial services, banking, atm operators, payment processing
Target regions
Asia-Pacific, Europe, Middle East, Africa
Detection rules
9
Indicators of compromise
24

Malware and tooling in UNC2891 Bank Heist

Malware and tooling: CAKETAP, SLAPSTICK, STEELCORGI, STEELHOUND, WINGCRACK, WINGHOOK, tsh, Custom TINYSHELL fork with AES-CBC encryption and single-byte XOR wrap, STEELCORGI (ELF packer)

How UNC2891 Bank Heist works

Financially motivated threat actor UNC2891 (LightBasin overlap) compromised an Asia-Pacific bank by physically planting a 4G LTE Raspberry Pi on a network switch sharing the ATM segment, established TINYSHELL C2 over Dynamic DNS, abused Linux bind mounts (T1564.013) for anti-forensics, and attempted to deploy the CAKETAP Solaris kernel rootkit on the ATM switching server to manipulate Payment HSM messages and authorize fraudulent withdrawals. Group-IB DFIR published the intrusion in July 2025; the same actor has targeted banking infrastructure on Linux, Unix and Oracle Solaris since at least 2017 with a custom toolkit including CAKETAP, SLAPSTICK, STEELHOUND, WINGHOOK and WINGCRACK.

## Overview

UNC2891 is a financially motivated intrusion set tracked by Mandiant since at least November 2017 with significant overlap to LightBasin (UNC1945). The group specializes in compromising Linux, Unix and Oracle Solaris infrastructure inside banking and telecommunications environments to monetize access to ATM switching, payment HSM, and SS7/SIGTRAN networks. In July 2025 Group-IB DFIR published a detailed case study of a 2024-2025 intrusion at an Asia-Pacific bank that combined a physical implant, custom Linux tooling, in-the-wild abuse of the newly cataloged MITRE technique T1564.013 (Hide Artifacts: Bind Mounts), and a near-miss attempt to deploy the CAKETAP rootkit on the bank's Oracle Solaris ATM switching server.

## Initial Access — Physical Raspberry Pi Implant

The intrusion did not begin at the perimeter. UNC2891 (or a contracted insider/lackey) physically planted a Raspberry Pi equipped with a 4G LTE modem on a network switch inside the ATM data center. The Pi was connected directly to a switch port carrying the ATM segment, giving the attackers a persistent, out-of-band channel that completely bypassed the bank's external firewall, IDS and network monitoring. The 4G modem provided cellular egress that did not traverse any corporate-monitored network path. This represents one of the most operationally bold initial-access vectors observed against a financial institution — it requires either a corrupted insider, a successful social-engineering of physical access, or a supply-chain attack on a hardware/maintenance vendor.

## Command and Control — TINYSHELL Over Dynamic DNS

Once inside, operators deployed TINYSHELL, a publicly available lightweight Unix backdoor that UNC2891 has heavily customized. The Raspberry Pi served as a hop-point: it ran a TINYSHELL beacon that connected outbound over its 4G uplink to a Dynamic DNS hostname controlled by the operators. Internal hosts on the ATM segment then connected to the Pi over the internal network and used it as a proxy/jump-host. TINYSHELL provides interactive shell, file transfer and TCP-tunnel primitives over a small, encrypted channel — UNC2891 variants commonly use a hardcoded AES key and a single-byte XOR obfuscation layer for traffic that crosses corporate boundaries.

## Defense Evasion — Linux Bind Mount Anti-Forensics (T1564.013)

The hallmark of this intrusion was UNC2891's use of Linux bind mounts to hide running processes and on-disk artifacts. The technique works as follows: an attacker creates a benign-looking directory under /tmp or a per-user runtime path, then issues `mount --bind` to overlay it on top of the /proc/<pid> directory of a malicious process. Tools that walk /proc (ps, top, htop, ls /proc) no longer see the process; the kernel still runs it normally. The same technique is applied to log files and tool binaries — bind-mounting an empty directory or a clean file over the real artifact path makes the artifact invisible to userland file scanners, EDR sensors that rely on path-based collection, and incident responders running standard triage. Group-IB explicitly worked with MITRE to catalog this behavior as T1564.013 (Hide Artifacts: Bind Mounts), published in 2025. The Linux command typically observed is `mount -o bind <empty_dir> /proc/<pid>` or `mount --bind /tmp/.cache/empty /var/log/secure`. Detection requires inspecting /proc/self/mountinfo for unexpected bind mounts that target /proc paths or sensitive log files.

## CAKETAP — Solaris Kernel Rootkit for Payment HSM Manipulation

The operators' end-goal was deployment of CAKETAP, a custom Oracle Solaris kernel-module rootkit first publicly described by Mandiant in March 2022. CAKETAP loads as a Solaris kernel module and hooks the kernel's network send/receive paths to inspect, modify and suppress messages between the bank's ATM switching server and the Payment HSM. Specifically, CAKETAP:

- Intercepts ISO 8583 financial-transaction messages and HSM PIN/card-verification responses; - Authorizes fraudulent withdrawals by modifying CVV/PIN-verification result fields so that mule-controlled cards with invalid credentials are approved; - Hides the rootkit's own kernel module from `modinfo` and `lsmod` output by unlinking from the module list and hooking the kernel module enumeration syscalls; - Receives operator commands via specially crafted TCP packets with a magic sequence; - Persists across reboots via a tampered driver configuration file.

In the 2025 Group-IB case the CAKETAP module was staged on the Pi and on a jump-host but had not yet been successfully loaded on the ATM switch when the intrusion was discovered.

## Lateral Movement and Credential Access

UNC2891 standard tradecraft seen in this and prior intrusions includes:

- **SLAPSTICK** — a PAM (Pluggable Authentication Modules) backdoor module compiled for Solaris and Linux. SLAPSTICK injects a hardcoded master password into PAM authentication; any local or SSH login that supplies the magic password is granted access, bypassing password files, LDAP, MFA and account lockouts. - **STEELHOUND** — an in-memory credential dumper for Solaris that decrypts and captures cleartext SSH keys and passwords used to authenticate to other Unix hosts. - **STEELCORGI** — an ELF packer used to hinder static analysis of UNC2891 binaries. - **WINGHOOK / WINGCRACK** — keylogger and parser pair targeting Unix terminals. - Heavy use of compromised SSH credentials harvested by STEELHOUND for east-west movement across the bank's Solaris and Linux fleet.

## Attribution and Targeting

UNC2891 has been active since at least November 2017 against banks, ATM operators and ATM switching providers in multiple regions. Mandiant assesses overlap with LightBasin (UNC1945), a group known for telco-targeted Unix tradecraft. Motivation is assessed as FINANCIAL — proceeds are realized by cashing out fraudulent ATM withdrawals through money mule networks. Attribution confidence to UNC2891 in the 2025 Group-IB case is HIGH based on the unique combination of CAKETAP, TINYSHELL configuration, SLAPSTICK PAM module hashes, and the bind-mount tradecraft. Nation-state attribution is not asserted; the group operates as a sophisticated cybercriminal collective with state-actor-grade Unix tradecraft.

## Defensive Implications

Defenders running Unix/Solaris infrastructure adjacent to payment systems should: (1) inventory all physical switch ports in ATM and HSM segments and disable unused ports with 802.1X; (2) audit /proc/self/mountinfo and /proc/mounts on all production Linux hosts for unexpected bind mounts referencing /proc or /var/log paths; (3) implement signed kernel modules and Secure Boot on Solaris ATM switching servers; (4) baseline PAM module hashes for pam_unix.so / pam_sm_authenticate functions; (5) monitor outbound DNS for unexpected Dynamic DNS hostnames originating from network-infrastructure VLANs; (6) inspect data center physical access logs in coincidence with anomalous switch port activations.

MITRE ATT&CK techniques used in TL-2026-0564

Credential Access

T1003.008 OS Credential Dumping: /etc/passwd and /etc/shadow; T1056.001 Input Capture: Keylogging; T1552.004 Unsecured Credentials: Private Keys

Collection

T1005 Data from Local System

Defense Evasion

T1014 Rootkit; T1027.002 Obfuscated Files or Information: Software Packing; T1036.005 Match Legitimate Resource Name or Location; T1070.004 Indicator Removal: File Deletion; T1564.013 Hide Artifacts: Bind Mounts

Lateral Movement

T1021.004 Remote Services: SSH

Discovery

T1057 Process Discovery; T1082 System Information Discovery

Execution

T1059.004 Command and Scripting Interpreter: Unix Shell

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1090 Proxy; T1568.002 Domain Generation Algorithms; T1571 Non-Standard Port; T1573.001 Encrypted Channel: Symmetric Cryptography

command-and-control

T1090.001 Internal Proxy

Initial Access

T1199 Trusted Relationship; T1200 Hardware Additions

Persistence

T1505 Server Software Component; T1547.006 Boot or Logon Autostart Execution: Kernel Modules and Extensions; T1556.003 Modify Authentication Process: Pluggable Authentication Modules

Privilege Escalation

T1548 Abuse Elevation Control Mechanism

Impact

T1565.002 Data Manipulation: Transmitted Data Manipulation; T1657 Financial Theft

Affected products and versions in UNC2891 Bank Heist

  • Oracle — Solaris
    Vulnerable versions: 10; 11.3; 11.4
    Fixed in: N/A — abuse of legitimate kernel module loading; mitigate via signed modules and Secure Boot
  • Linux — Kernel (bind mount feature)
    Vulnerable versions: All current kernels supporting mount --bind
    Fixed in: N/A — legitimate kernel feature; mitigate via auditd, namespaces, IMA
  • Various — ATM switching servers and Payment HSM gateways
    Vulnerable versions: Any Unix/Linux/Solaris based ATM switch with kernel-module load privilege

Remediation for UNC2891 Bank Heist

Patches

  • Patch Oracle Solaris to currently supported release with all kernel security fixes; legacy Solaris 10 ATM switches should be migrated.
  • Update Linux kernels to a version supporting unprivileged user namespace restrictions and audit hooks for mount operations.

Immediate actions

  • Audit all physical switch ports in ATM and HSM network segments; disable unused ports and enforce 802.1X port authentication.
  • Run `cat /proc/self/mountinfo | grep -E '/proc/[0-9]+|/var/log'` on every production Linux host and investigate any unexpected bind mounts.
  • Inventory Solaris kernel modules with `modinfo` and compare against a known-good baseline; investigate any unsigned or unfamiliar modules.
  • Search outbound DNS logs for queries to Dynamic DNS providers (duckdns.org, no-ip.com, dynu.net, afraid.org) originating from server VLANs.
  • Hash and verify all PAM modules (pam_unix.so and friends) against vendor distribution hashes; replace any drift.

Workarounds

  • Apply auditd rules: `-a always,exit -F arch=b64 -S mount -k mount_ops` to log all mount syscalls on Linux.
  • Restrict CAP_SYS_ADMIN on user accounts; bind mount abuse requires root or CAP_SYS_ADMIN.
  • Block egress to cellular/4G ranges from any host other than approved out-of-band management appliances.

Longer-term hardening

  • Deploy host-based EDR with kernel-resident sensors on Solaris ATM switching servers and Linux hosts adjacent to payment HSMs.
  • Implement Secure Boot and signed kernel modules on Solaris where supported; use IMA/EVM on Linux.
  • Segment ATM/payment network with hardware enclaves; require jump-host with strong session recording for any administrative access.
  • Conduct quarterly physical inspections of network closets; install tamper-evident seals and CCTV coverage on switch ports.
  • Adopt Group-IB / Mandiant YARA rules for CAKETAP, TINYSHELL, SLAPSTICK, STEELHOUND in periodic file system sweeps.

Weaknesses (CWE) in UNC2891 Bank Heist

CWE-1188, CWE-501, CWE-940, CWE-693

Timeline of UNC2891 Bank Heist

  • Mandiant first observes UNC2891 activity targeting banking and telecommunications infrastructure on Linux, Unix and Solaris systems.
  • CrowdStrike publishes 'LightBasin: A Roaming Threat to Telecommunications Companies' describing tradecraft later linked to UNC2891 via UNC1945 overlap.
  • Mandiant publishes 'Have Your Cake and Eat it Too?' — first public description of CAKETAP Solaris rootkit, SLAPSTICK, STEELHOUND, STEELCORGI and the UNC2891 toolkit.
  • BleepingComputer and other outlets cover CAKETAP and the UNC2891 ATM-targeting toolkit.
  • Estimated start of the Asia-Pacific bank intrusion: physical Raspberry Pi implant planted on a network switch sharing the ATM segment.
  • MITRE publishes ATT&CK technique T1564.013 (Hide Artifacts: Bind Mounts), based on collaboration with Group-IB on the UNC2891 case.
  • TINYSHELL beacon on Raspberry Pi establishes C2 over 4G LTE to operator-controlled Dynamic DNS hostname; lateral movement into ATM switching environment begins.
  • CAKETAP Solaris kernel module staged on the Raspberry Pi and an internal jump-host in preparation for deployment to the ATM switching server.
  • Bank detects anomalous behavior and engages Group-IB DFIR; CAKETAP had not yet been loaded on the production ATM switch.
  • Group-IB publishes 'UNC2891 Bank Heist' DFIR report detailing the Raspberry Pi implant, TINYSHELL C2, bind-mount anti-forensics and the attempted CAKETAP deployment.
  • The Hacker News, BleepingComputer and other outlets publish coverage of the Group-IB UNC2891 disclosure.
  • The Register publishes 'Cybercrooks use Raspberry Pi to steal ATM cash' covering operator use of physical implants and bribed insiders.
  • As of 2026-05-29, the specific Group-IB-reported intrusion was foiled before CAKETAP loaded, but UNC2891 (LightBasin overlap) was never arrested or taken down and retains its full custom Unix/Solaris arsenal (CAKETAP, TINYSHELL, SLAPSTICK). No CVE to patch (legitimate-feature abuse), so the financially-motivated actor and bind-mount tradecraft remain a live, resurgent concern for banking infrastructure.

Sources cited for UNC2891 Bank Heist

Detection coverage for TL-2026-0564

As of 2026-05-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0564 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
24 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats