SLAPSTICK is a Pluggable Authentication Module (PAM) backdoor and credential harvester used against Linux and Unix systems, including Oracle Solaris. It replaces a legitimate PAM authentication module, captures user authentication details, and stores the collected information in encrypted local logs. The implant accepts passwords beginning with a hardcoded secret prefix, allowing attackers to bypass normal authentication. Its additional functionality includes shell-command execution, file deletion, and TCP proxying.
SLAPSTICK is associated with UNC2891 and has also been observed in the toolkit shared with UNC1945. In financially motivated UNC2891 intrusions against Indonesian banks, it supported persistent access and lateral movement through compromised servers and banking infrastructure. Operators used its authentication bypass alongside SSH and legitimate accounts to access additional systems and transfer tools. Some deployments used host-specific secret passwords. SLAPSTICK operates within a broader toolset that includes TINYSHELL backdoors and the CAKETAP rootkit, but ATM transaction manipulation is a capability of CAKETAP rather than SLAPSTICK.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SLAPSTICK is a Linux PAM (Pluggable Authentication Module) with a capability to harvest the user authentication data and act as a backdoor.
SLAPSTICK is a Linux PAM (Pluggable Authentication Module) with a capability to harvest the user authentication data and act as a backdoor.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Mandiant has documented the activities of a team it's called UNC2891 and its targeting of Solaris systems with backdoors dubbed TINYSHELL and SLAPSTICK and a rootkit called CAKETAP.
The threat actor employed multiple obfuscation techniques, including payload and string encryption.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux/UNIX-targeting malware attributed in the content to UNC2891; detection described as matching specific format-string sequences in ELF binaries.
PAM backdoor providing covert authentication access ("magical password") used for persistence on Unix-like systems.
A backdoor used against Solaris systems in activity attributed by Mandiant to UNC2891.
A malware/tool linked to LightBasin and still deployed in its attacks; the content states LightBasin uses Caketap, Slapstick, and Tinyshell in every step.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.