CAKETAP is a Unix kernel-module rootkit associated with the financially motivated threat actor UNC2891, also tracked as LightBasin. It has been observed on Oracle Solaris systems and is used in intrusions targeting banking infrastructure, particularly ATM switching environments. The malware is designed for stealth and fraud enablement: it hides files, processes, and network connections on compromised hosts, removes evidence of its presence from kernel module listings, and hooks multiple system functions to receive operator commands and apply filtering rules. Reported command functionality includes modifying filtering behavior, adding or removing network filters, and restoring the module’s visibility when needed.
A notable CAKETAP variant was developed to interfere with payment transaction flows on ATM switch servers. It intercepts card and PIN verification traffic destined for hardware security modules and can spoof authorization responses for attacker-controlled fraudulent cards while preserving normal processing for legitimate customer transactions to reduce operational disruption and detection risk. This behavior supports unauthorized ATM cash withdrawals as part of broader bank fraud operations.
CAKETAP has been documented alongside other UNC2891 tooling, including TINYSHELL and SLAPSTICK, in campaigns characterized by deep expertise in Unix and Linux environments, strong operational security, and targeting of poorly monitored mission-critical systems. In later intrusion reporting, UNC2891 sought to position itself inside bank networks through covert access methods and then deploy CAKETAP on the ATM switching server as the final fraud-enabling payload.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
LightBasin's new rootkit is a Unix kernel module named "Caketap" that is deployed on servers running the Oracle Solaris operating system.
LightBasin's new rootkit is a Unix kernel module named "Caketap" that is deployed on servers running the Oracle Solaris operating system.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
LightBasin's new rootkit is a Unix kernel module named "Caketap" that is deployed on servers running the Oracle Solaris operating system. When loaded, Caketap hides network connections, processes, and files while installing several hooks into system functions to receive remote commands and configurations.
When loaded, Caketap hides network connections, processes, and files while installing several hooks into system functions to receive remote commands and configurations.
The ultimate goal of Caketap is to intercept banking card and PIN verification data from breached ATM switch servers and then use the stolen data to facilitate unauthorized transactions. The messages intercepted by Caketap are destined for the Payment Hardware Security Module (HSM)...
The ultimate goal of Caketap is to intercept banking card and PIN verification data from breached ATM switch servers and then use the stolen data to facilitate unauthorized transactions. The messages intercepted by Caketap are destined for the Payment Hardware Security Module (HSM)...
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Unix/Oracle Solaris kernel-module rootkit used to manipulate ATM switching servers. It hides network connections, processes, and files, and intercepts and spoofs HSM card and PIN verification messages so fraudulent ATM transactions are authorized.
A rootkit intended for deployment on ATM switching servers to manipulate HSM responses and spoof authorization messages in support of fraudulent ATM cash withdrawals.
Rootkit used/attempted in ATM-focused fraud intrusion (per summary).
Custom Solaris/Linux rootkit used by UNC2891 in long-dwell intrusions against ATM switching/production environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.