UNC2891 Bank Heist Explained: CAKETAP Rootkit and Raspberry Pi Attack

Umut Bayram | 8 MIN READ

| May 22, 2026

Key Takeaways

  • UNC2891 is a financially motivated threat group active since at least November 2017, targeting banking infrastructure with expertise in Linux, Unix, and Oracle Solaris environments.
  • The group runs a custom malware arsenal including CAKETAP (Solaris kernel rootkit), TINYSHELL (backdoor), SLAPSTICK (PAM backdoor), STEELHOUND (in-memory dropper), WINGHOOK (keylogger), and WINGCRACK (decoder).
  • In Q1 2025, operators physically planted a 4G-enabled Raspberry Pi on a network switch sharing the same segment as an ATM at an Asia-Pacific bank, bypassing perimeter defenses.
  • A specialized CAKETAP variant on ATM switch servers manipulated messages to the Payment HSM, bypassing card verification and replaying PIN verification responses to authorize fraudulent cash withdrawals.
  • You can test your defenses against UNC2891 using Threat ID 94587 (UNC2891 Threat Group Campaign) in the Picus Security Validation Platform.

UNC2891 is a financially motivated threat group active since at least November 2017. The group targets banking infrastructure with deep expertise in Linux, Unix, and Oracle Solaris environments. UNC2891 operates a custom malware arsenal including CAKETAP, TINYSHELL, SLAPSTICK, STEELHOUND, WINGHOOK, and WINGCRACK to compromise ATM switching systems and authorize fraudulent cash withdrawals.

In this blog, we will review UNC2891's major historical operations, examine their intrusions against banks, and break down the group's tactics, techniques, and procedures to show how they compromise ATM infrastructure for financial gain. In the end, we will show how Picus Platform helps defend against this group.

Simulate APT Attacks with 14-Day Free Trial of Picus Platform

What Are the Major Activities of the UNC2891?

November 2017 (at least) – UNC2891 began operating as a financially motivated threat actor with deep expertise in Linux, Unix, and Oracle Solaris environments, with the earliest known compromises traced to this period across ATM switching servers and production systems of banking targets.

February 2022 – An Indonesian bank was breached, with more than 30 systems across the network compromised in preparation for coordinated ATM cash-outs.

November 2023 – A second Indonesian bank was compromised in a separate intrusion.

Q1 2025 – A 4G-enabled Raspberry Pi was physically planted on a network switch sharing the same segment as an ATM at an Asia-Pacific bank.

Which MITRE ATT&CK Techniques Are Used by UNC2891?

Tactic: Resource Development

T1583.001 Acquire Infrastructure: Domains

UNC2891 registered dynamic DNS (DDNS) domains for command and control operations. Each compromised host received its own unique domain, and subdomains sometimes mirrored the hostname of the target machine. IP resolution for these domains appeared to activate only during short windows when network access was required.

Dynamic domain <hostname-of-target-machine>.<attacker-domain>.<tld>

T1587.001 Develop Capabilities: Malware

UNC2891 built or modified a custom malware arsenal.

  • CAKETAP: Oracle Solaris kernel rootkit.
  • STEELHOUND: In-memory dropper.
  • WINGHOOK: Unix and Linux keylogger shared library.
  • WINGCRACK: Decoder utility. Reads and displays the encoded "schwing" keylog files produced by WINGHOOK.
  • TINYSHELL (custom variant): Lightweight backdoor.

Tactic: Initial Access

T1200 Hardware Additions

UNC2891 physically installed a Raspberry Pi equipped with a 4G modem inside a bank's network. The device connected to the same switch as an ATM, placing the attacker directly inside the internal network and bypassing perimeter defenses entirely.

Tactic: Execution

T1059.004 Command and Scripting Interpreter: Unix Shell

UNC2891 executed shell commands to control CAKETAP. Operators issued mkdir commands containing a signal string and a single-character command suffix to trigger rootkit functions, hooked into the syscall, mkdirat.

# Add network filter for 192.168.1.10:80

mkdir /some/path/.caahGss187I192.168.1.10p80


# Display current configuration

mkdir /some/path/.caahGss187S

Breakdown of the command format [1]:

  • .caahGss187: The magic prefix. CAKETAP inspects every mkdirat call and acts only when a path segment starts with this exact string. Normal mkdir calls without this prefix pass through untouched.
  • Character after the prefix: The command selector. One character tells CAKETAP which action to run.
    • I adds a network filter.
    • S displays the current configuration.
    • Other selectors include M, i, P, p, and empty. These have different functionalities.
  • Text after the selector: The argument for the command. In I192.168.1.10p80, the I selector takes 192.168.1.10 as the IP and p80 as the port to filter.

Tactic: Persistence

T1543.002 Create or Modify System Process: Systemd Service

UNC2891 installed systemd service unit files to keep the TINYSHELL backdoor running across reboots.

<unit file path>

[Unit]
Description=<service description>

[Service]
Type=forking
ExecStart=<path to executable>

[Install]
WantedBy=<systemd target>

T1556.003 Modify Authentication Process: Pluggable Authentication Modules

UNC2891 heavily relied on SLAPSTICK, a PAM-based backdoor. SLAPSTICK granted persistent access through a hardcoded magical password and logged authentication attempts along with plaintext passwords to an encrypted file. Part of the decrypted file is shown below [1]:

2021 Jan 16 14:10:06 /usr/sbin/sshd sshd user1 plaintextpassword server1 Authentication failure


2021 Jan 18 22:50:45 /usr/sbin/sshd sshd root rBa4JZpFABIHj67rWONnk29 172.16.10.10 Magical password


2021 Mar 22 20:15:06 /usr/sbin/sshd sshd user4 plaintextpassword 10.10.10.102 Success

This log file also allowed the attacker to capture credentials.

Tactic: Defense Evasion

T1014 Rootkit

UNC2891 deployed CAKETAP. On load, CAKETAP removed itself from the loaded modules list and updated the last_module_id to point to the previously loaded module.

CAKETAP hid network connections, processes, and files. It placed hooks into ipcl_get_next_conn and other functions in the ip module to filter connections matching operator-configured IP addresses or ports.

Some other hooks targeted the mkdirat and getdents64 system calls.

T1036.005 Masquerading: Match Legitimate Resource Name or Location

UNC2891 renamed TINYSHELL backdoors to impersonate legitimate services, including systemd, name service cache daemon (NCSD), and the Linux at daemon (ATD).

The group also ran backdoor binaries named lightdm to mimic the LightDM display manager. Command-line arguments were crafted to resemble legitimate session parameters [2]:

lightdm --session 11 19

T1070.002 Indicator Removal: Clear Linux or Mac System Logs

UNC2891 used WIPERIGHT to remove log entries tied to a specified user from lastlog, utmp/utmpx, wtmp/wtmpx, and pacct files.

They also used MIGLOGCLEANER to wipe logs or stripped targeted strings from logs on Linux and Unix systems.

T1140 Deobfuscate/Decode Files or Information

UNC2891 used STEELHOUND, an in-memory dropper that decrypts embedded payloads through RC4 encryption. The decryption key was taken from environment variables. The closely related STEELCORGI dropper used ChaCha20.

They also used WINGCRACK to decode the "schwing" files produced by the WINGHOOK keylogger.

T1564.013 Hide Artifacts: Bind Mounts

UNC2891 abused Linux bind mounts to hide backdoor processes.

A bind mount takes an existing file or directory and makes its contents appear at a second location. You run mount --bind /source /target. Any process reading /target now sees what lives at /source. The original content at /target still exists on disk, but the kernel hides it behind the mount.

Linux stores process information in /proc/[pid]. Tools like ps, netstat, lsof, and ss read these directories to link processes to sockets, files, and command lines.

Because the attacker bind-mounted over /proc/[pid] entries [2], these tools failed to associate sockets with any process, giving attackers stealth.

tmpfs on /proc/1234 type tmpfs (rw,nosuid,nodev)


# Explanation:

PID 8239 is the backdoor process.

An empty tmpfs (in-memory filesystem) sits mounted on top of /proc/1234.

Any query for process 1234 hits the empty tmpfs. No command line. No open files. No socket links.

Tactic: Collection

T1056.001 Input Capture: Keylogging

UNC2891 deployed WINGHOOK, a Unix and Linux keylogger packaged as a shared library (SO file).

WINGHOOK hooked the read and fgets functions to capture user input. Captured data was stored in an encoded format under /var/tmp/ with filenames beginning with .zmanDw.

Tactic: Command and Control

T1090 Proxy

Some TINYSHELL variants supported communication through an HTTP proxy with basic authentication.

UNC2891 also built multi-hop C2 paths by chaining TINYSHELL variants across compromised internal servers.

T1095 Non-Application Layer Protocol

TINYSHELL backdoors communicated over raw TCP on ports 53 and 443. This choice helped blend malicious traffic with normal network flows and slip past outbound filtering.

Tactic: Impact

T1565.002 Data Manipulation: Transmitted Data Manipulation

A specialized CAKETAP variant on a victim ATM switch server intercepted messages sent to the Payment Hardware Security Module (HSM). The rootkit ran two manipulations [1]:

  • Card verification bypass: CAKETAP changed the mode of outgoing messages to skip card verification. The HSM returned a valid response without checking. Fraudulent cards carried a PAN-based marker generated by a custom algorithm. CAKETAP matched the marker, flagged the card, and saved the PAN in memory.
  • PIN verification replay: CAKETAP checked outgoing PIN verification messages. Legitimate messages passed through untouched. Messages tied to flagged PANs got swapped with saved message content, replaying a prior valid response and bypassing PIN checks.

UNC2891 used this variant to authorize unauthorized ATM cash withdrawals with fraudulent cards across several banks.

How Picus Simulates UNC2891 Attacks?

We also strongly suggest simulating UNC2891 Attacks to test the effectiveness of your security controls against real-life cyber attacks using the Picus Security Validation Platform. You can also test your defenses against hundreds of other threat groups within minutes with a 14-day free trial of the Picus Platform.

Picus Threat Library includes the following threats for UNC2891:

Threat ID

Threat Name

Attack Module

94587

UNC2891 Threat Group Campaign

Linux Endpoint

Start simulating emerging threats today and get actionable mitigation insights with a 14-day free trial of the Picus Security Validation Platform.

References

[1] “Have Your Cake and Eat it Too? An Overview of UNC2891,” Google Cloud Blog. Accessed: Apr. 24, 2026. [Online]. Available: https://cloud.google.com/blog/topics/threat-intelligence/unc2891-overview

[2] Y. Mazurenka, “UNC2891 Bank Heist: Physical ATM Backdoor & Linux Forensic Evasion,” Group-IB. Accessed: Apr. 24, 2026. [Online]. Available: https://www.group-ib.com/blog/unc2891-bank-heist/

 
UNC2891 is a financially motivated threat group active since at least November 2017. The group targets banking infrastructure and holds deep expertise in Linux, Unix, and Oracle Solaris environments. UNC2891 operates a custom malware arsenal including CAKETAP, TINYSHELL, SLAPSTICK, STEELHOUND, WINGHOOK, and WINGCRACK to compromise ATM switching systems and authorize fraudulent cash withdrawals.
UNC2891 aims to authorize unauthorized ATM cash withdrawals with fraudulent cards across banks. The group compromises ATM switching servers and uses a specialized CAKETAP variant to intercept messages sent to the Payment Hardware Security Module (HSM), bypassing card verification and PIN verification checks to enable coordinated cash-outs.
In Q1 2025, UNC2891 physically installed a Raspberry Pi equipped with a 4G modem inside a bank's network at an Asia-Pacific bank. The device connected to the same switch as an ATM, placing the attacker directly inside the internal network and bypassing perimeter defenses entirely.
CAKETAP is an Oracle Solaris kernel rootkit. On load, CAKETAP removes itself from the loaded modules list and hides network connections, processes, and files. Operators control CAKETAP through mkdir commands containing a magic prefix ".caahGss187" and a single-character command selector that triggers rootkit functions like adding network filters or displaying configuration.
A specialized CAKETAP variant on victim ATM switch servers performs two manipulations. For card verification bypass, CAKETAP changes outgoing message modes so the HSM returns valid responses without checking. For PIN verification replay, CAKETAP swaps messages tied to flagged PANs with saved valid response content, replaying prior approvals.
UNC2891 uses Linux bind mounts to hide backdoor processes, deploys the CAKETAP rootkit to hide network connections and files, and installs systemd services for TINYSHELL persistence. The group relies on SLAPSTICK PAM backdoor for credential capture, wipes logs with WIPERIGHT and MIGLOGCLEANER, captures keystrokes with WINGHOOK, and communicates over TCP ports 53 and 443 through dynamic DNS domains.
Picus Security Validation Platform simulates UNC2891 attacks to test the effectiveness of your security controls against real-life cyber threats. The Picus Threat Library includes the UNC2891 Threat Group Campaign (Threat ID 94587) for the Linux Endpoint attack module.

Table of Contents

Ready to start? Request a demo