Threat actors tracked as UNC2891 infiltrated a bank by gaining physical access to its ATM network and installing a Raspberry Pi equipped with a 4G modem, creating an out-of-band foothold into internal systems. From that access, the attackers deployed the TINYSHELL backdoor and moved through the bank’s network monitoring and mail servers in an effort to reach the ATM switching server, where they intended to install CAKETAP, a rootkit designed to manipulate HSM responses and authorize fraudulent ATM cash withdrawals.
Investigators said the intrusion was unusually difficult to detect because the attackers used Linux bind mounts to hide malicious processes and files from standard forensic triage, a defense-evasion method now tracked as MITRE ATT&CK T1564.013. The hidden malware masqueraded as lightdm and beaconed every 600 seconds, but memory analysis and network forensics ultimately uncovered the activity and exposed the attackers’ persistence mechanisms. The operation was disrupted before UNC2891 could complete the cash-out phase of the attack.

See the actors and campaigns active against you right now.
7 events from the most recent confirmed update back to the earliest known activity.
The Linux bind-mount artifact-hiding technique highlighted in the investigation is now tracked by MITRE ATT&CK as T1564.013.
The campaign was stopped before UNC2891 achieved its final objective of manipulating ATM infrastructure to enable fraudulent cash withdrawals.
Investigators ultimately uncovered the compromise through memory analysis and network forensics, identifying beaconing every 600 seconds and the concealed backdoor activity.
The intrusion used Linux bind mounts to conceal malware artifacts and processes, causing standard forensic triage to miss a hidden backdoor process masquerading as "lightdm."
Investigators found the attackers used the custom TINYSHELL backdoor and were aiming to deploy the CAKETAP rootkit to manipulate HSM responses and enable fraudulent ATM cash withdrawals.
After establishing access, UNC2891 moved through the environment using the network monitoring server and mail server as pivots while attempting to reach the ATM switching server.
Attackers attributed to UNC2891 physically installed a Raspberry Pi with a 4G modem on the bank's ATM network to establish covert access into the banking environment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.