logo

UNC2891 Bank Heist Explained: CAKETAP Rootkit and Raspberry Pi Attack

ID: c2145961-3da4-5b65-9379-5091a035e20a

STIX ID: report--c2145961-3da4-5b65-9379-5091a035e20a

Feed Name: Resources-2

Threat Score
80/100

Date Published: 2026-05-22

Date Updated: 2026-07-22

Author: [email protected] (Umut Bayram)

...
...

UNC2891 is a financially motivated threat group active since at least November 2017 that targets banking infrastructure—particularly Linux, Unix, and Oracle Solaris ATM switching systems—using a custom malware arsenal (CAKETAP, TINYSHELL, SLAPSTICK, STEELHOUND, WINGHOOK, WINGCRACK) and physical implants (a 4G Raspberry Pi) to bypass perimeter defenses, manipulate HSM communications, and authorize fraudulent ATM withdrawals; the report catalogs their timeline, TTPs mapped to MITRE ATT&CK, malware behaviors, forensic evasion techniques, and simulation/testing guidance via the Picus platform.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.