Threat reportAPTTL-2026-0564
UNC2891 Bank Heist — CAKETAP Solaris Rootkit and 4G Raspberry Pi Physical Implant Targeting ATM Switching Network
UNC2891 Bank Heist (TL-2026-0564), also tracked as UNC2891 Bank Heist, is a critical-severity advanced persistent threat campaign, first published 2026-05-22. It is attributed to UNC2891 with high confidence, affects Oracle Solaris, maps to 27 MITRE ATT&CK techniques (T1003.008, T1005, T1014), and is covered by 9 detection rules and 24 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 27MITRE ATT&CK
- Actors
- 1UNC2891
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 24Indicators of compromise
Key facts for TL-2026-0564
- Threat ID
- TL-2026-0564
- Also known as
- UNC2891 Bank Heist, CAKETAP ATM Heist, Asia-Pacific Bank Pi Implant
- Severity
- CRITICAL
- Status
- MONITORING
- Category
- APT
- First published
- Last reviewed
- Attribution
- UNC2891
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- financial services, banking, atm operators, payment processing
- Target regions
- Asia-Pacific, Europe, Middle East, Africa
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in UNC2891 Bank Heist
Malware and tooling: CAKETAP, SLAPSTICK, STEELCORGI, STEELHOUND, WINGCRACK, WINGHOOK, tsh, Custom TINYSHELL fork with AES-CBC encryption and single-byte XOR wrap, STEELCORGI (ELF packer)
How UNC2891 Bank Heist works
Financially motivated threat actor UNC2891 (LightBasin overlap) compromised an Asia-Pacific bank by physically planting a 4G LTE Raspberry Pi on a network switch sharing the ATM segment, established TINYSHELL C2 over Dynamic DNS, abused Linux bind mounts (T1564.013) for anti-forensics, and attempted to deploy the CAKETAP Solaris kernel rootkit on the ATM switching server to manipulate Payment HSM messages and authorize fraudulent withdrawals. Group-IB DFIR published the intrusion in July 2025; the same actor has targeted banking infrastructure on Linux, Unix and Oracle Solaris since at least 2017 with a custom toolkit including CAKETAP, SLAPSTICK, STEELHOUND, WINGHOOK and WINGCRACK.
## Overview
UNC2891 is a financially motivated intrusion set tracked by Mandiant since at least November 2017 with significant overlap to LightBasin (UNC1945). The group specializes in compromising Linux, Unix and Oracle Solaris infrastructure inside banking and telecommunications environments to monetize access to ATM switching, payment HSM, and SS7/SIGTRAN networks. In July 2025 Group-IB DFIR published a detailed case study of a 2024-2025 intrusion at an Asia-Pacific bank that combined a physical implant, custom Linux tooling, in-the-wild abuse of the newly cataloged MITRE technique T1564.013 (Hide Artifacts: Bind Mounts), and a near-miss attempt to deploy the CAKETAP rootkit on the bank's Oracle Solaris ATM switching server.
## Initial Access — Physical Raspberry Pi Implant
The intrusion did not begin at the perimeter. UNC2891 (or a contracted insider/lackey) physically planted a Raspberry Pi equipped with a 4G LTE modem on a network switch inside the ATM data center. The Pi was connected directly to a switch port carrying the ATM segment, giving the attackers a persistent, out-of-band channel that completely bypassed the bank's external firewall, IDS and network monitoring. The 4G modem provided cellular egress that did not traverse any corporate-monitored network path. This represents one of the most operationally bold initial-access vectors observed against a financial institution — it requires either a corrupted insider, a successful social-engineering of physical access, or a supply-chain attack on a hardware/maintenance vendor.
## Command and Control — TINYSHELL Over Dynamic DNS
Once inside, operators deployed TINYSHELL, a publicly available lightweight Unix backdoor that UNC2891 has heavily customized. The Raspberry Pi served as a hop-point: it ran a TINYSHELL beacon that connected outbound over its 4G uplink to a Dynamic DNS hostname controlled by the operators. Internal hosts on the ATM segment then connected to the Pi over the internal network and used it as a proxy/jump-host. TINYSHELL provides interactive shell, file transfer and TCP-tunnel primitives over a small, encrypted channel — UNC2891 variants commonly use a hardcoded AES key and a single-byte XOR obfuscation layer for traffic that crosses corporate boundaries.
## Defense Evasion — Linux Bind Mount Anti-Forensics (T1564.013)
The hallmark of this intrusion was UNC2891's use of Linux bind mounts to hide running processes and on-disk artifacts. The technique works as follows: an attacker creates a benign-looking directory under /tmp or a per-user runtime path, then issues `mount --bind` to overlay it on top of the /proc/<pid> directory of a malicious process. Tools that walk /proc (ps, top, htop, ls /proc) no longer see the process; the kernel still runs it normally. The same technique is applied to log files and tool binaries — bind-mounting an empty directory or a clean file over the real artifact path makes the artifact invisible to userland file scanners, EDR sensors that rely on path-based collection, and incident responders running standard triage. Group-IB explicitly worked with MITRE to catalog this behavior as T1564.013 (Hide Artifacts: Bind Mounts), published in 2025. The Linux command typically observed is `mount -o bind <empty_dir> /proc/<pid>` or `mount --bind /tmp/.cache/empty /var/log/secure`. Detection requires inspecting /proc/self/mountinfo for unexpected bind mounts that target /proc paths or sensitive log files.
## CAKETAP — Solaris Kernel Rootkit for Payment HSM Manipulation
The operators' end-goal was deployment of CAKETAP, a custom Oracle Solaris kernel-module rootkit first publicly described by Mandiant in March 2022. CAKETAP loads as a Solaris kernel module and hooks the kernel's network send/receive paths to inspect, modify and suppress messages between the bank's ATM switching server and the Payment HSM. Specifically, CAKETAP:
- Intercepts ISO 8583 financial-transaction messages and HSM PIN/card-verification responses; - Authorizes fraudulent withdrawals by modifying CVV/PIN-verification result fields so that mule-controlled cards with invalid credentials are approved; - Hides the rootkit's own kernel module from `modinfo` and `lsmod` output by unlinking from the module list and hooking the kernel module enumeration syscalls; - Receives operator commands via specially crafted TCP packets with a magic sequence; - Persists across reboots via a tampered driver configuration file.
In the 2025 Group-IB case the CAKETAP module was staged on the Pi and on a jump-host but had not yet been successfully loaded on the ATM switch when the intrusion was discovered.
## Lateral Movement and Credential Access
UNC2891 standard tradecraft seen in this and prior intrusions includes:
- **SLAPSTICK** — a PAM (Pluggable Authentication Modules) backdoor module compiled for Solaris and Linux. SLAPSTICK injects a hardcoded master password into PAM authentication; any local or SSH login that supplies the magic password is granted access, bypassing password files, LDAP, MFA and account lockouts. - **STEELHOUND** — an in-memory credential dumper for Solaris that decrypts and captures cleartext SSH keys and passwords used to authenticate to other Unix hosts. - **STEELCORGI** — an ELF packer used to hinder static analysis of UNC2891 binaries. - **WINGHOOK / WINGCRACK** — keylogger and parser pair targeting Unix terminals. - Heavy use of compromised SSH credentials harvested by STEELHOUND for east-west movement across the bank's Solaris and Linux fleet.
## Attribution and Targeting
UNC2891 has been active since at least November 2017 against banks, ATM operators and ATM switching providers in multiple regions. Mandiant assesses overlap with LightBasin (UNC1945), a group known for telco-targeted Unix tradecraft. Motivation is assessed as FINANCIAL — proceeds are realized by cashing out fraudulent ATM withdrawals through money mule networks. Attribution confidence to UNC2891 in the 2025 Group-IB case is HIGH based on the unique combination of CAKETAP, TINYSHELL configuration, SLAPSTICK PAM module hashes, and the bind-mount tradecraft. Nation-state attribution is not asserted; the group operates as a sophisticated cybercriminal collective with state-actor-grade Unix tradecraft.
## Defensive Implications
Defenders running Unix/Solaris infrastructure adjacent to payment systems should: (1) inventory all physical switch ports in ATM and HSM segments and disable unused ports with 802.1X; (2) audit /proc/self/mountinfo and /proc/mounts on all production Linux hosts for unexpected bind mounts referencing /proc or /var/log paths; (3) implement signed kernel modules and Secure Boot on Solaris ATM switching servers; (4) baseline PAM module hashes for pam_unix.so / pam_sm_authenticate functions; (5) monitor outbound DNS for unexpected Dynamic DNS hostnames originating from network-infrastructure VLANs; (6) inspect data center physical access logs in coincidence with anomalous switch port activations.
MITRE ATT&CK techniques used in TL-2026-0564
Credential Access
T1003.008 OS Credential Dumping: /etc/passwd and /etc/shadow; T1056.001 Input Capture: Keylogging; T1552.004 Unsecured Credentials: Private Keys
Collection
Defense Evasion
T1014 Rootkit; T1027.002 Obfuscated Files or Information: Software Packing; T1036.005 Match Legitimate Resource Name or Location; T1070.004 Indicator Removal: File Deletion; T1564.013 Hide Artifacts: Bind Mounts
Lateral Movement
T1021.004 Remote Services: SSH
Discovery
T1057 Process Discovery; T1082 System Information Discovery
Execution
T1059.004 Command and Scripting Interpreter: Unix Shell
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1090 Proxy; T1568.002 Domain Generation Algorithms; T1571 Non-Standard Port; T1573.001 Encrypted Channel: Symmetric Cryptography
command-and-control
Initial Access
T1199 Trusted Relationship; T1200 Hardware Additions
Persistence
T1505 Server Software Component; T1547.006 Boot or Logon Autostart Execution: Kernel Modules and Extensions; T1556.003 Modify Authentication Process: Pluggable Authentication Modules
Privilege Escalation
T1548 Abuse Elevation Control Mechanism
Impact
T1565.002 Data Manipulation: Transmitted Data Manipulation; T1657 Financial Theft
Affected products and versions in UNC2891 Bank Heist
- Oracle — Solaris
Vulnerable versions: 10; 11.3; 11.4
Fixed in: N/A — abuse of legitimate kernel module loading; mitigate via signed modules and Secure Boot - Linux — Kernel (bind mount feature)
Vulnerable versions: All current kernels supporting mount --bind
Fixed in: N/A — legitimate kernel feature; mitigate via auditd, namespaces, IMA - Various — ATM switching servers and Payment HSM gateways
Vulnerable versions: Any Unix/Linux/Solaris based ATM switch with kernel-module load privilege
Remediation for UNC2891 Bank Heist
Patches
- Patch Oracle Solaris to currently supported release with all kernel security fixes; legacy Solaris 10 ATM switches should be migrated.
- Update Linux kernels to a version supporting unprivileged user namespace restrictions and audit hooks for mount operations.
Immediate actions
- Audit all physical switch ports in ATM and HSM network segments; disable unused ports and enforce 802.1X port authentication.
- Run `cat /proc/self/mountinfo | grep -E '/proc/[0-9]+|/var/log'` on every production Linux host and investigate any unexpected bind mounts.
- Inventory Solaris kernel modules with `modinfo` and compare against a known-good baseline; investigate any unsigned or unfamiliar modules.
- Search outbound DNS logs for queries to Dynamic DNS providers (duckdns.org, no-ip.com, dynu.net, afraid.org) originating from server VLANs.
- Hash and verify all PAM modules (pam_unix.so and friends) against vendor distribution hashes; replace any drift.
Workarounds
- Apply auditd rules: `-a always,exit -F arch=b64 -S mount -k mount_ops` to log all mount syscalls on Linux.
- Restrict CAP_SYS_ADMIN on user accounts; bind mount abuse requires root or CAP_SYS_ADMIN.
- Block egress to cellular/4G ranges from any host other than approved out-of-band management appliances.
Longer-term hardening
- Deploy host-based EDR with kernel-resident sensors on Solaris ATM switching servers and Linux hosts adjacent to payment HSMs.
- Implement Secure Boot and signed kernel modules on Solaris where supported; use IMA/EVM on Linux.
- Segment ATM/payment network with hardware enclaves; require jump-host with strong session recording for any administrative access.
- Conduct quarterly physical inspections of network closets; install tamper-evident seals and CCTV coverage on switch ports.
- Adopt Group-IB / Mandiant YARA rules for CAKETAP, TINYSHELL, SLAPSTICK, STEELHOUND in periodic file system sweeps.
Weaknesses (CWE) in UNC2891 Bank Heist
Timeline of UNC2891 Bank Heist
- Mandiant first observes UNC2891 activity targeting banking and telecommunications infrastructure on Linux, Unix and Solaris systems.
- CrowdStrike publishes 'LightBasin: A Roaming Threat to Telecommunications Companies' describing tradecraft later linked to UNC2891 via UNC1945 overlap.
- Mandiant publishes 'Have Your Cake and Eat it Too?' — first public description of CAKETAP Solaris rootkit, SLAPSTICK, STEELHOUND, STEELCORGI and the UNC2891 toolkit.
- BleepingComputer and other outlets cover CAKETAP and the UNC2891 ATM-targeting toolkit.
- Estimated start of the Asia-Pacific bank intrusion: physical Raspberry Pi implant planted on a network switch sharing the ATM segment.
- MITRE publishes ATT&CK technique T1564.013 (Hide Artifacts: Bind Mounts), based on collaboration with Group-IB on the UNC2891 case.
- TINYSHELL beacon on Raspberry Pi establishes C2 over 4G LTE to operator-controlled Dynamic DNS hostname; lateral movement into ATM switching environment begins.
- CAKETAP Solaris kernel module staged on the Raspberry Pi and an internal jump-host in preparation for deployment to the ATM switching server.
- Bank detects anomalous behavior and engages Group-IB DFIR; CAKETAP had not yet been loaded on the production ATM switch.
- Group-IB publishes 'UNC2891 Bank Heist' DFIR report detailing the Raspberry Pi implant, TINYSHELL C2, bind-mount anti-forensics and the attempted CAKETAP deployment.
- The Hacker News, BleepingComputer and other outlets publish coverage of the Group-IB UNC2891 disclosure.
- The Register publishes 'Cybercrooks use Raspberry Pi to steal ATM cash' covering operator use of physical implants and bribed insiders.
- As of 2026-05-29, the specific Group-IB-reported intrusion was foiled before CAKETAP loaded, but UNC2891 (LightBasin overlap) was never arrested or taken down and retains its full custom Unix/Solaris arsenal (CAKETAP, TINYSHELL, SLAPSTICK). No CVE to patch (legitimate-feature abuse), so the financially-motivated actor and bind-mount tradecraft remain a live, resurgent concern for banking infrastructure.
Sources cited for UNC2891 Bank Heist
- UNC2891 Bank Heist: Physical ATM Backdoor and Linux Forensic Evasion
- Have Your Cake and Eat it Too? An Overview of UNC2891 (Mandiant)
- New Unix rootkit used to steal ATM banking data
- UNC2891 Breaches ATM Network via 4G Raspberry Pi, Tries CAKETAP Rootkit for Fraud
- Cybercrooks use Raspberry Pi to steal ATM cash
- MITRE ATT&CK T1564.013 — Hide Artifacts: Bind Mounts
- MITRE ATT&CK Group G1006 (LightBasin)
- CrowdStrike — LightBasin: A Roaming Threat to Telecommunications Companies
- MITRE ATT&CK T1014 — Rootkit
- MITRE ATT&CK T1556.003 — Modify Authentication Process: Pluggable Authentication Modules
Detection coverage for TL-2026-0564
As of 2026-05-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0564 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.