# UNC2891 Bank Heist — CAKETAP Solaris Rootkit and 4G Raspberry Pi Physical Implant Targeting ATM Switching Network

> Financially motivated threat actor UNC2891 (LightBasin overlap) compromised an Asia-Pacific bank by physically planting a 4G LTE Raspberry Pi on a network switch sharing the ATM segment, established TINYSHELL C2 over Dynamic DNS, abused Linux bind mounts (T1564.013) for anti-forensics, and attempted to deploy the CAKETAP Solaris kernel rootkit on the ATM switching server to manipulate Payment HSM messages and authorize fraudulent withdrawals. Group-IB DFIR published the intrusion in July 2025; the same actor has targeted banking infrastructure on Linux, Unix and Oracle Solaris since at least 2017 with a custom toolkit including CAKETAP, SLAPSTICK, STEELHOUND, WINGHOOK and WINGCRACK.

- **Published:** 2026-05-22T12:00:00Z
- **Last reviewed:** 2026-05-22T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0564
- **ID:** TL-2026-0564
- **Severity:** CRITICAL
- **Category:** APT
- **Status:** MONITORING
- **Actor:** UNC2891
- **Detections:** 9 · **IOCs:** 24 (full data via the Threadlinqs MCP server — Purple tier)

## Description

## Overview

UNC2891 is a financially motivated intrusion set tracked by Mandiant since at least November 2017 with significant overlap to LightBasin (UNC1945). The group specializes in compromising Linux, Unix and Oracle Solaris infrastructure inside banking and telecommunications environments to monetize access to ATM switching, payment HSM, and SS7/SIGTRAN networks. In July 2025 Group-IB DFIR published a detailed case study of a 2024-2025 intrusion at an Asia-Pacific bank that combined a physical implant, custom Linux tooling, in-the-wild abuse of the newly cataloged MITRE technique T1564.013 (Hide Artifacts: Bind Mounts), and a near-miss attempt to deploy the CAKETAP rootkit on the bank's Oracle Solaris ATM switching server.

## Initial Access — Physical Raspberry Pi Implant

The intrusion did not begin at the perimeter. UNC2891 (or a contracted insider/lackey) physically planted a Raspberry Pi equipped with a 4G LTE modem on a network switch inside the ATM data center. The Pi was connected directly to a switch port carrying the ATM segment, giving the attackers a persistent, out-of-band channel that completely bypassed the bank's external firewall, IDS and network monitoring. The 4G modem provided cellular egress that did not traverse any corporate-monitored network path. This represents one of the most operationally bold initial-access vectors observed against a financial institution — it requires either a corrupted insider, a successful social-engineering of physical access, or a supply-chain attack on a hardware/maintenance vendor.

## Command and Control — TINYSHELL Over Dynamic DNS

Once inside, operators deployed TINYSHELL, a publicly available lightweight Unix backdoor that UNC2891 has heavily customized. The Raspberry Pi served as a hop-point: it ran a TINYSHELL beacon that connected outbound over its 4G uplink to a Dynamic DNS hostname controlled by the operators. Internal hosts on the ATM segment then connected to the Pi over the internal network and used it as a proxy/jump-host. TINYSHELL provides interactive shell, file transfer and TCP-tunnel primitives over a small, encrypted channel — UNC2891 variants commonly use a hardcoded AES key and a single-byte XOR obfuscation layer for traffic that crosses corporate boundaries.

## Defense Evasion — Linux Bind Mount Anti-Forensics (T1564.013)

The hallmark of this intrusion was UNC2891's use of Linux bind mounts to hide running processes and on-disk artifacts. The technique works as follows: an attacker creates a benign-looking directory under /tmp or a per-user runtime path, then issues `mount --bind` to overlay it on top of the /proc/<pid> directory of a malicious process. Tools that walk /proc (ps, top, htop, ls /proc) no longer see the process; the kernel still runs it normally. The same technique is applied to log files and tool binaries — bind-mounting an empty directory or a clean file over the real artifact path makes the artifact invisible to userland file scanners, EDR sensors that rely on path-based collection, and incident responders running standard triage. Group-IB explicitly worked with MITRE to catalog this behavior as T1564.013 (Hide Artifacts: Bind Mounts), published in 2025. The Linux command typically observed is `mount -o bind <empty_dir> /proc/<pid>` or `mount --bind /tmp/.cache/empty /var/log/secure`. Detection requires inspecting /proc/self/mountinfo for unexpected bind mounts that target /proc paths or sensitive log files.

## CAKETAP — Solaris Kernel Rootkit for Payment HSM Manipulation

The operators' end-goal was deployment of CAKETAP, a custom Oracle Solaris kernel-module rootkit first publicly described by Mandiant in March 2022. CAKETAP loads as a Solaris kernel module and hooks the kernel's network send/receive paths to inspect, modify and suppress messages between the bank's ATM switching server and the Payment HSM. Specifically, CAKETAP:

- Intercepts ISO 8583 financial-transaction messages and HSM PIN/card-verification responses;
- Authorizes fraudulent withdrawals by modifying CVV/PIN-verification result fields so that mule-controlled cards with invalid credentials are approved;
- Hides the rootkit's own kernel module from `modinfo` and `lsmod` output by unlinking from the module list and hooking the kernel module enumeration syscalls;
- Receives operator commands via specially crafted TCP packets with a magic sequence;
- Persists across reboots via a tampered driver configuration file.

In the 2025 Group-IB case the CAKETAP module was staged on the Pi and on a jump-host but had not yet been successfully loaded on the ATM switch when the intrusion was discovered.

## Lateral Movement and Credential Access

UNC2891 standard tradecraft seen in this and prior intrusions includes:

- **SLAPSTICK** — a PAM (Pluggable Authentication Modules) backdoor module compiled for Solaris and Linux. SLAPSTICK injects a hardcoded master password into PAM authentication; any local or SSH login that supplies the magic password is granted access, bypassing password files, LDAP, MFA and account lockouts.
- **STEELHOUND** — an in-memory credential dumper for Solaris that decrypts and captures cleartext SSH keys and passwords used to authenticate to other Unix hosts.
- **STEELCORGI** — an ELF packer used to hinder static analysis of UNC2891 binaries.
- **WINGHOOK / WINGCRACK** — keylogger and parser pair targeting Unix terminals.
- Heavy use of compromised SSH credentials harvested by STEELHOUND for east-west movement across the bank's Solaris and Linux fleet.

## Attribution and Targeting

UNC2891 has been active since at least November 2017 against banks, ATM operators and ATM switching providers in multiple regions. Mandiant assesses overlap with LightBasin (UNC1945), a group known for telco-targeted Unix tradecraft. Motivation is assessed as FINANCIAL — proceeds are realized by cashing out fraudulent ATM withdrawals through money mule networks. Attribution confidence to UNC2891 in the 2025 Group-IB case is HIGH based on the unique combination of CAKETAP, TINYSHELL configuration, SLAPSTICK PAM module hashes, and the bind-mount tradecraft. Nation-state attribution is not asserted; the group operates as a sophisticated cybercriminal collective with state-actor-grade Unix tradecraft.

## Defensive Implications

Defenders running Unix/Solaris infrastructure adjacent to payment systems should: (1) inventory all physical switch ports in ATM and HSM segments and disable unused ports with 802.1X; (2) audit /proc/self/mountinfo and /proc/mounts on all production Linux hosts for unexpected bind mounts referencing /proc or /var/log paths; (3) implement signed kernel modules and Secure Boot on Solaris ATM switching servers; (4) baseline PAM module hashes for pam_unix.so / pam_sm_authenticate functions; (5) monitor outbound DNS for unexpected Dynamic DNS hostnames originating from network-infrastructure VLANs; (6) inspect data center physical access logs in coincidence with anomalous switch port activations.

## MITRE ATT&CK

- T1200 Hardware Additions
- T1199 Trusted Relationship
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1547.006 Boot or Logon Autostart Execution: Kernel Modules and Extensions
- T1556.003 Modify Authentication Process: Pluggable Authentication Modules
- T1505 Server Software Component
- T1548 Abuse Elevation Control Mechanism
- T1014 Rootkit
- T1564.013 Hide Artifacts: Bind Mounts
- T1070.004 Indicator Removal: File Deletion
- T1027.002 Obfuscated Files or Information: Software Packing
- T1036.005 Match Legitimate Resource Name or Location
- T1003.008 OS Credential Dumping: /etc/passwd and /etc/shadow
- T1056.001 Input Capture: Keylogging
- T1552.004 Unsecured Credentials: Private Keys
- T1082 System Information Discovery
- T1057 Process Discovery
- T1021.004 Remote Services: SSH
- T1090.001 Internal Proxy
- T1005 Data from Local System
- T1071.001 Application Layer Protocol: Web Protocols
- T1568.002 Domain Generation Algorithms
- T1573.001 Encrypted Channel: Symmetric Cryptography
- T1090 Proxy
- T1571 Non-Standard Port
- T1657 Financial Theft
- T1565.002 Data Manipulation: Transmitted Data Manipulation

## Sources

- [UNC2891 Bank Heist: Physical ATM Backdoor and Linux Forensic Evasion](https://www.group-ib.com/blog/unc2891-bank-heist/)
- [Have Your Cake and Eat it Too? An Overview of UNC2891 (Mandiant)](https://cloud.google.com/blog/topics/threat-intelligence/unc2891-overview/)
- [New Unix rootkit used to steal ATM banking data](https://www.bleepingcomputer.com/news/security/new-unix-rootkit-used-to-steal-atm-banking-data/)
- [UNC2891 Breaches ATM Network via 4G Raspberry Pi, Tries CAKETAP Rootkit for Fraud](https://thehackernews.com/2025/07/unc2891-breaches-atm-network-via-4g.html)
- [Cybercrooks use Raspberry Pi to steal ATM cash](https://www.theregister.com/2025/08/01/cybercrooks_bribed_lackeys_in_physical/)
- [MITRE ATT&CK T1564.013 — Hide Artifacts: Bind Mounts](https://attack.mitre.org/techniques/T1564/013/)
- [MITRE ATT&CK Group G1006 (LightBasin)](https://attack.mitre.org/groups/G1006/)
- [CrowdStrike — LightBasin: A Roaming Threat to Telecommunications Companies](https://www.crowdstrike.com/blog/an-analysis-of-lightbasin-telecommunications-attacks/)
- [MITRE ATT&CK T1014 — Rootkit](https://attack.mitre.org/techniques/T1014/)
- [MITRE ATT&CK T1556.003 — Modify Authentication Process: Pluggable Authentication Modules](https://attack.mitre.org/techniques/T1556/003/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0564
