CAKETAP is a Unix kernel-module rootkit associated with the financially motivated threat actor UNC2891. It has been deployed on compromised Oracle Solaris servers, including ATM switching infrastructure, to conceal attacker activity and facilitate fraudulent ATM cash withdrawals.
The rootkit hides files, processes, network connections, and its own presence in the loaded-module list. It hooks system functions to filter network connections, conceal filesystem entries, and accept commands and configuration changes through specially crafted system-call requests. Its controls support changes to concealment filters and inspection of its configuration.
A variant deployed on ATM switching servers intercepts card and PIN verification traffic exchanged with payment hardware security modules (HSMs). It recognizes attacker-designated fraudulent cards, suppresses their verification requests, and generates approval responses. It can also retain and replay legitimate verification data to bypass PIN checks while forwarding ordinary customer transactions to avoid disrupting banking operations. These capabilities support unauthorized withdrawals using fraudulent bank cards.
CAKETAP is deployed after attackers gain access to banking server infrastructure rather than acting as an initial-access mechanism. UNC2891 has used it alongside backdoors such as TINYSHELL and SLAPSTICK. Other investigated banking intrusions were interrupted before the attackers could complete their intended CAKETAP deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC2891 deployed a range of custom malware, including CAKETAP (a Solaris/Linux rootkit).
LightBasin's new rootkit is a Unix kernel module named "Caketap" that is deployed on servers running the Oracle Solaris operating system.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
CAKETAP also employs stealth mechanisms to conceal its presence by removing evidence of its kernel installation.
When loaded, Caketap hides network connections, processes, and files while installing several hooks into system functions to receive remote commands and configurations.
The ultimate goal of Caketap is to intercept banking card and PIN verification data from breached ATM switch servers and then use the stolen data to facilitate unauthorized transactions. The messages intercepted by Caketap are destined for the Payment Hardware Security Module (HSM)...
The ultimate goal of Caketap is to intercept banking card and PIN verification data from breached ATM switch servers and then use the stolen data to facilitate unauthorized transactions. The messages intercepted by Caketap are destined for the Payment Hardware Security Module (HSM)...
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Unix/Oracle Solaris kernel-module rootkit used to manipulate ATM switching servers. It hides network connections, processes, and files, and intercepts and spoofs HSM card and PIN verification messages so fraudulent ATM transactions are authorized.
A rootkit intended for deployment on ATM switching servers to manipulate HSM responses and spoof authorization messages in support of fraudulent ATM cash withdrawals.
Rootkit used/attempted in ATM-focused fraud intrusion (per summary).
Custom Solaris/Linux rootkit used by UNC2891 in long-dwell intrusions against ATM switching/production environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.