Cybercrooks attached Raspberry Pi to bank network and drained ATM cash
ID: 98b4d3a1-05bc-567a-b9d5-658a89f71270
STIX ID: report--98b4d3a1-05bc-567a-b9d5-658a89f71270
Feed Name: The Register (Security)
UNC2891 operators physically implanted a 4G-connected Raspberry Pi onto a bank network in Q1 2024 to gain persistent access and execute ATM cash withdrawals. They deployed the Tinyshell backdoor with dynamic DNS C2, used Linux bind-mount techniques to hide processes, and planned to use the Caketap rootkit to spoof authorization messages; the intrusion was detected and mitigated after an initial cashout, underscoring sophisticated cross-platform capabilities and the need for memory and network forensics beyond standard playbooks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
