SLAPSTICK is a Unix Pluggable Authentication Module backdoor associated with the financially motivated threat actor UNC2891, also known as LightBasin. It has been observed in intrusions targeting mission-critical Unix environments, particularly Oracle Solaris systems, alongside other custom tooling such as TINYSHELL and the CAKETAP rootkit. UNC2891 has used this malware in operations linked to compromises of ATM switching and related financial infrastructure, as well as broader activity against poorly monitored Unix and Linux systems.
SLAPSTICK is characterized as a PAM backdoor that enables covert access through a secret or "magical" password mechanism, allowing an operator to authenticate without normal credentials. This design supports stealthy persistence on compromised systems by subverting the host authentication stack rather than relying solely on conventional remote-access services. Its deployment alongside rootkit and backdoor tooling indicates use in sustained post-compromise access and operator-controlled maintenance of footholds on high-value servers.
The malware is part of a broader UNC2891 toolkit used in long-running financially motivated intrusions. Reporting ties the actor’s operations to bank card fraud and unauthorized ATM cash-out activity, with SLAPSTICK serving as one component of the access and persistence layer on targeted Unix infrastructure. High-confidence reporting specifically places it on Solaris-focused victim environments, though the actor’s wider tradecraft also spans Linux systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Other tools linked to the actor in previous attacks include Slapstick, Tinyshell, Steelhound, Steelcorgi, Wingjook, Wingcrack, Binbash, Wiperight, and the Mignogcleaner, all of which Mandiant confirmed as still deployed in LightBasin attacks.
Mandiant has documented the activities of a team it's called UNC2891 and its targeting of Solaris systems with backdoors dubbed TINYSHELL and SLAPSTICK and a rootkit called CAKETAP.
1 distinct technique documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux/UNIX-targeting malware attributed in the content to UNC2891; detection described as matching specific format-string sequences in ELF binaries.
PAM backdoor providing covert authentication access ("magical password") used for persistence on Unix-like systems.
A backdoor used against Solaris systems in activity attributed by Mandiant to UNC2891.
A malware/tool linked to LightBasin and still deployed in its attacks; the content states LightBasin uses Caketap, Slapstick, and Tinyshell in every step.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.