UNC2891 is a financially motivated cybercriminal threat cluster active since at least November 2017 that primarily targets banking infrastructure, including ATM switching systems. Its operations include intrusions against Indonesian financial institutions and demonstrate extensive expertise in Linux, Unix, and Oracle Solaris. UNC2891 shares tooling and techniques with UNC1945, also known as LightBasin, but these overlaps do not establish that the clusters are the same actor. Its country of origin is not established. The actor uses custom backdoors, credential stealers, keyloggers, encrypted in-memory droppers, and anti-forensic utilities to maintain long-term access. Its toolkit includes TINYSHELL for remote shells and file transfer; SLAPSTICK, a malicious pluggable authentication module that captures credentials and bypasses authentication; WINGHOOK for keylogging; STEELCORGI and STEELHOUND for encrypted payload delivery; and SUN4ME for reconnaissance, scanning, brute forcing, and other post-compromise operations. UNC2891 moves laterally through SSH, legitimate accounts, and authentication backdoors, and establishes persistence through modified system binaries and startup services. Defense-evasion techniques include log manipulation, timestomping, process masquerading, environment-variable-based payload decryption, and Linux bind-mount abuse to conceal malicious processes from conventional inspection. UNC2891 has physically connected a 4G-equipped Raspberry Pi to an ATM-connected network switch, creating an internal foothold with cellular remote connectivity that bypassed perimeter defenses. It used compromised monitoring infrastructure for lateral movement and maintained an additional backdoor on an internet-facing mail server, preserving access after the rogue device was removed. A central component of its financial-fraud operations is CAKETAP, a Solaris kernel-module rootkit that conceals malicious activity and intercepts ATM card and PIN verification traffic to payment hardware security modules. CAKETAP manipulates authorization exchanges to enable unauthorized ATM withdrawals using fraudulent cards. The actor also coordinates money mules to prepare cards and conduct cash withdrawals under remote direction.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
59 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
24 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated intrusions against banks and ATM/payment infrastructure, including a cyber-physical attack using a Raspberry Pi with 4G for out-of-band C2, Linux bind-mount anti-forensics, lateral movement via a network monitoring server, and planned deployment of CAKETAP to spoof HSM authorization messages and enable fraudulent ATM cash-outs.
Financially motivated intrusion set targeting banking infrastructure, using physical access via a Raspberry Pi implanted in the ATM network, stealthy Linux anti-forensics with bind mounts, hidden backdoors on internal servers, and multi-pivot access to reach an ATM switching server for fraudulent cash-out operations.
Financially motivated actor targeting ATM networks via on-site hardware implantation (4G Raspberry Pi) and attempting deployment of CAKETAP rootkit for fraud.
Referenced as the source/attribution for the SLAPSTICK Linux/UNIX malware family; the content does not describe operations beyond this attribution.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.