UNC2891 Bank Heist Explained: CAKETAP Rootkit and Raspberry Pi Attack
| May 22, 2026
Key Takeaways
- UNC2891 is a financially motivated threat group active since at least November 2017, targeting banking infrastructure with expertise in Linux, Unix, and Oracle Solaris environments.
- The group runs a custom malware arsenal including CAKETAP (Solaris kernel rootkit), TINYSHELL (backdoor), SLAPSTICK (PAM backdoor), STEELHOUND (in-memory dropper), WINGHOOK (keylogger), and WINGCRACK (decoder).
- In Q1 2025, operators physically planted a 4G-enabled Raspberry Pi on a network switch sharing the same segment as an ATM at an Asia-Pacific bank, bypassing perimeter defenses.
- A specialized CAKETAP variant on ATM switch servers manipulated messages to the Payment HSM, bypassing card verification and replaying PIN verification responses to authorize fraudulent cash withdrawals.
- You can test your defenses against UNC2891 using Threat ID 94587 (UNC2891 Threat Group Campaign) in the Picus Security Validation Platform.
UNC2891 is a financially motivated threat group active since at least November 2017. The group targets banking infrastructure with deep expertise in Linux, Unix, and Oracle Solaris environments. UNC2891 operates a custom malware arsenal including CAKETAP, TINYSHELL, SLAPSTICK, STEELHOUND, WINGHOOK, and WINGCRACK to compromise ATM switching systems and authorize fraudulent cash withdrawals.
In this blog, we will review UNC2891's major historical operations, examine their intrusions against banks, and break down the group's tactics, techniques, and procedures to show how they compromise ATM infrastructure for financial gain. In the end, we will show how Picus Platform helps defend against this group.
Simulate APT Attacks with 14-Day Free Trial of Picus Platform
What Are the Major Activities of the UNC2891?
November 2017 (at least) – UNC2891 began operating as a financially motivated threat actor with deep expertise in Linux, Unix, and Oracle Solaris environments, with the earliest known compromises traced to this period across ATM switching servers and production systems of banking targets.
February 2022 – An Indonesian bank was breached, with more than 30 systems across the network compromised in preparation for coordinated ATM cash-outs.
November 2023 – A second Indonesian bank was compromised in a separate intrusion.
Q1 2025 – A 4G-enabled Raspberry Pi was physically planted on a network switch sharing the same segment as an ATM at an Asia-Pacific bank.
Which MITRE ATT&CK Techniques Are Used by UNC2891?
Tactic: Resource Development
T1583.001 Acquire Infrastructure: Domains
UNC2891 registered dynamic DNS (DDNS) domains for command and control operations. Each compromised host received its own unique domain, and subdomains sometimes mirrored the hostname of the target machine. IP resolution for these domains appeared to activate only during short windows when network access was required.
|
Dynamic domain <hostname-of-target-machine>.<attacker-domain>.<tld> |
T1587.001 Develop Capabilities: Malware
UNC2891 built or modified a custom malware arsenal.
- CAKETAP: Oracle Solaris kernel rootkit.
- STEELHOUND: In-memory dropper.
- WINGHOOK: Unix and Linux keylogger shared library.
- WINGCRACK: Decoder utility. Reads and displays the encoded "schwing" keylog files produced by WINGHOOK.
- TINYSHELL (custom variant): Lightweight backdoor.
Tactic: Initial Access
T1200 Hardware Additions
UNC2891 physically installed a Raspberry Pi equipped with a 4G modem inside a bank's network. The device connected to the same switch as an ATM, placing the attacker directly inside the internal network and bypassing perimeter defenses entirely.
Tactic: Execution
T1059.004 Command and Scripting Interpreter: Unix Shell
UNC2891 executed shell commands to control CAKETAP. Operators issued mkdir commands containing a signal string and a single-character command suffix to trigger rootkit functions, hooked into the syscall, mkdirat.
|
# Add network filter for 192.168.1.10:80 mkdir /some/path/.caahGss187I192.168.1.10p80 # Display current configuration mkdir /some/path/.caahGss187S |
Breakdown of the command format [1]:
- .caahGss187: The magic prefix. CAKETAP inspects every mkdirat call and acts only when a path segment starts with this exact string. Normal mkdir calls without this prefix pass through untouched.
- Character after the prefix: The command selector. One character tells CAKETAP which action to run.
- I adds a network filter.
- S displays the current configuration.
- Other selectors include M, i, P, p, and empty. These have different functionalities.
- Text after the selector: The argument for the command. In I192.168.1.10p80, the I selector takes 192.168.1.10 as the IP and p80 as the port to filter.
Tactic: Persistence
T1543.002 Create or Modify System Process: Systemd Service
UNC2891 installed systemd service unit files to keep the TINYSHELL backdoor running across reboots.
|
<unit file path> |
T1556.003 Modify Authentication Process: Pluggable Authentication Modules
UNC2891 heavily relied on SLAPSTICK, a PAM-based backdoor. SLAPSTICK granted persistent access through a hardcoded magical password and logged authentication attempts along with plaintext passwords to an encrypted file. Part of the decrypted file is shown below [1]:
|
2021 Jan 16 14:10:06 /usr/sbin/sshd sshd user1 plaintextpassword server1 Authentication failure
|
This log file also allowed the attacker to capture credentials.
Tactic: Defense Evasion
T1014 Rootkit
UNC2891 deployed CAKETAP. On load, CAKETAP removed itself from the loaded modules list and updated the last_module_id to point to the previously loaded module.
CAKETAP hid network connections, processes, and files. It placed hooks into ipcl_get_next_conn and other functions in the ip module to filter connections matching operator-configured IP addresses or ports.
Some other hooks targeted the mkdirat and getdents64 system calls.
T1036.005 Masquerading: Match Legitimate Resource Name or Location
UNC2891 renamed TINYSHELL backdoors to impersonate legitimate services, including systemd, name service cache daemon (NCSD), and the Linux at daemon (ATD).
The group also ran backdoor binaries named lightdm to mimic the LightDM display manager. Command-line arguments were crafted to resemble legitimate session parameters [2]:
|
lightdm --session 11 19 |
T1070.002 Indicator Removal: Clear Linux or Mac System Logs
UNC2891 used WIPERIGHT to remove log entries tied to a specified user from lastlog, utmp/utmpx, wtmp/wtmpx, and pacct files.
They also used MIGLOGCLEANER to wipe logs or stripped targeted strings from logs on Linux and Unix systems.
T1140 Deobfuscate/Decode Files or Information
UNC2891 used STEELHOUND, an in-memory dropper that decrypts embedded payloads through RC4 encryption. The decryption key was taken from environment variables. The closely related STEELCORGI dropper used ChaCha20.
They also used WINGCRACK to decode the "schwing" files produced by the WINGHOOK keylogger.
T1564.013 Hide Artifacts: Bind Mounts
UNC2891 abused Linux bind mounts to hide backdoor processes.
A bind mount takes an existing file or directory and makes its contents appear at a second location. You run mount --bind /source /target. Any process reading /target now sees what lives at /source. The original content at /target still exists on disk, but the kernel hides it behind the mount.
Linux stores process information in /proc/[pid]. Tools like ps, netstat, lsof, and ss read these directories to link processes to sockets, files, and command lines.
Because the attacker bind-mounted over /proc/[pid] entries [2], these tools failed to associate sockets with any process, giving attackers stealth.
|
tmpfs on /proc/1234 type tmpfs (rw,nosuid,nodev) # Explanation: PID 8239 is the backdoor process. An empty tmpfs (in-memory filesystem) sits mounted on top of /proc/1234. Any query for process 1234 hits the empty tmpfs. No command line. No open files. No socket links. |
Tactic: Collection
T1056.001 Input Capture: Keylogging
UNC2891 deployed WINGHOOK, a Unix and Linux keylogger packaged as a shared library (SO file).
WINGHOOK hooked the read and fgets functions to capture user input. Captured data was stored in an encoded format under /var/tmp/ with filenames beginning with .zmanDw.
Tactic: Command and Control
T1090 Proxy
Some TINYSHELL variants supported communication through an HTTP proxy with basic authentication.
UNC2891 also built multi-hop C2 paths by chaining TINYSHELL variants across compromised internal servers.
T1095 Non-Application Layer Protocol
TINYSHELL backdoors communicated over raw TCP on ports 53 and 443. This choice helped blend malicious traffic with normal network flows and slip past outbound filtering.
Tactic: Impact
T1565.002 Data Manipulation: Transmitted Data Manipulation
A specialized CAKETAP variant on a victim ATM switch server intercepted messages sent to the Payment Hardware Security Module (HSM). The rootkit ran two manipulations [1]:
- Card verification bypass: CAKETAP changed the mode of outgoing messages to skip card verification. The HSM returned a valid response without checking. Fraudulent cards carried a PAN-based marker generated by a custom algorithm. CAKETAP matched the marker, flagged the card, and saved the PAN in memory.
- PIN verification replay: CAKETAP checked outgoing PIN verification messages. Legitimate messages passed through untouched. Messages tied to flagged PANs got swapped with saved message content, replaying a prior valid response and bypassing PIN checks.
UNC2891 used this variant to authorize unauthorized ATM cash withdrawals with fraudulent cards across several banks.
How Picus Simulates UNC2891 Attacks?
We also strongly suggest simulating UNC2891 Attacks to test the effectiveness of your security controls against real-life cyber attacks using the Picus Security Validation Platform. You can also test your defenses against hundreds of other threat groups within minutes with a 14-day free trial of the Picus Platform.
Picus Threat Library includes the following threats for UNC2891:
|
Threat ID |
Threat Name |
Attack Module |
|
94587 |
UNC2891 Threat Group Campaign |
Linux Endpoint |
Start simulating emerging threats today and get actionable mitigation insights with a 14-day free trial of the Picus Security Validation Platform.
References
[1] “Have Your Cake and Eat it Too? An Overview of UNC2891,” Google Cloud Blog. Accessed: Apr. 24, 2026. [Online]. Available: https://cloud.google.com/blog/topics/threat-intelligence/unc2891-overview
[2] Y. Mazurenka, “UNC2891 Bank Heist: Physical ATM Backdoor & Linux Forensic Evasion,” Group-IB. Accessed: Apr. 24, 2026. [Online]. Available: https://www.group-ib.com/blog/unc2891-bank-heist/
