UNC2891 is a financially motivated threat cluster active since at least 2017 that specializes in covert intrusions against banking infrastructure, particularly ATM switching environments. The actor is notable for deep expertise across Linux, Unix, and Oracle Solaris systems and for using custom malware and anti-forensic tradecraft to support fraudulent ATM cash-out operations. UNC2891 has been linked to attacks in which the operators sought to compromise ATM switching servers and manipulate hardware security module authorization workflows to enable unauthorized withdrawals using fraudulent cards. A core malware family associated with the cluster is CAKETAP, a Unix and Solaris kernel rootkit used to hide processes, files, and network connections and, in ATM-focused operations, to intercept and spoof card-and-PIN verification or related authorization messages. Other tooling associated with UNC2891 includes TINYSHELL for command-and-control, SLAPSTICK, WINGHOOK and WINGCRACK, in-memory droppers such as STEELCORGI and STEELHOUND, and log-clearing or privilege-oriented utilities including WIPERIGHT, MIGLOGCLEANER, and BINBASH. Reporting also describes a broader toolkit referred to as SUN4ME. The actor has demonstrated unusual cyber-physical tradecraft. In one documented bank intrusion, operators physically implanted a 4G-enabled Raspberry Pi into ATM-connected network infrastructure to obtain an internal foothold while bypassing perimeter defenses. From that access, UNC2891 pivoted through a network monitoring server, maintained persistence through an internet-facing mail server, and used TINYSHELL-backed implants masquerading as legitimate Linux processes. The group employed a novel Linux bind-mount anti-forensics technique to hide malicious processes from standard triage by obscuring entries in the proc filesystem, forcing responders to rely on memory and network forensics rather than disk-based analysis alone. UNC2891 also uses credential-collection and surveillance capabilities on Unix-like systems. WINGHOOK is a Linux and Unix keylogger implemented as a shared library that hooks input-related functions, while WINGCRACK decodes the captured output. The cluster has used in-memory payload decryption keyed from environment variables, uuencoding wrappers, log wiping, process masquerading, and root-level utilities to support stealth, persistence, and post-compromise operations. Mandiant has documented overlaps between UNC2891 and UNC1945, also known as LightBasin, but publicly available reporting stops short of conclusively treating them as the same actor. UNC2891 is best characterized as a highly capable cybercriminal cluster focused on financial fraud against banking and ATM transaction infrastructure, with advanced Unix-centric malware development and strong operational security.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated intrusions against banks and ATM/payment infrastructure, including a cyber-physical attack using a Raspberry Pi with 4G for out-of-band C2, Linux bind-mount anti-forensics, lateral movement via a network monitoring server, and planned deployment of CAKETAP to spoof HSM authorization messages and enable fraudulent ATM cash-outs.
Financially motivated intrusion set targeting banking infrastructure, using physical access via a Raspberry Pi implanted in the ATM network, stealthy Linux anti-forensics with bind mounts, hidden backdoors on internal servers, and multi-pivot access to reach an ATM switching server for fraudulent cash-out operations.
Financially motivated actor targeting ATM networks via on-site hardware implantation (4G Raspberry Pi) and attempting deployment of CAKETAP rootkit for fraud.
Referenced as the source/attribution for the SLAPSTICK Linux/UNIX malware family; the content does not describe operations beyond this attribution.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.