logo

Hackers plant 4G Raspberry Pi on bank network in failed ATM heist

ID: d3bae5e3-4ee0-595c-b0d6-364de80e64a1

STIX ID: report--d3bae5e3-4ee0-595c-b0d6-364de80e64a1

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-07-30

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

UNC2891 (LightBasin) executed a sophisticated hybrid physical+remote intrusion at a bank by planting a 4G-enabled Raspberry Pi on the ATM network switch to create an outbound TinyShell C2 channel, enabling lateral movement to monitoring and mail servers, persistence via backdoors disguised as legitimate services, and attempted deployment of the Caketap rootkit to spoof ATM authorizations and facilitate fraudulent cash withdrawals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.