logo

Cybercrooks attached Raspberry Pi to bank network and drained ATM cash

ID: 98b4d3a1-05bc-567a-b9d5-658a89f71270

STIX ID: report--98b4d3a1-05bc-567a-b9d5-658a89f71270

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-08-01

Date Updated: 2026-04-26

Author: Connor Jones

...
...

UNC2891 operators physically implanted a 4G-connected Raspberry Pi onto a bank network in Q1 2024 to gain persistent access and execute ATM cash withdrawals. They deployed the Tinyshell backdoor with dynamic DNS C2, used Linux bind-mount techniques to hide processes, and planned to use the Caketap rootkit to spoof authorization messages; the intrusion was detected and mitigated after an initial cashout, underscoring sophisticated cross-platform capabilities and the need for memory and network forensics beyond standard playbooks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.