UNC2891 Bank Heist Explained: CAKETAP Rootkit and Raspberry Pi Attack
ID: c2145961-3da4-5b65-9379-5091a035e20a
STIX ID: report--c2145961-3da4-5b65-9379-5091a035e20a
Feed Name: Resources-2
UNC2891 is a financially motivated threat group active since at least November 2017 that targets banking infrastructure—particularly Linux, Unix, and Oracle Solaris ATM switching systems—using a custom malware arsenal (CAKETAP, TINYSHELL, SLAPSTICK, STEELHOUND, WINGHOOK, WINGCRACK) and physical implants (a 4G Raspberry Pi) to bypass perimeter defenses, manipulate HSM communications, and authorize fraudulent ATM withdrawals; the report catalogs their timeline, TTPs mapped to MITRE ATT&CK, malware behaviors, forensic evasion techniques, and simulation/testing guidance via the Picus platform.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
