Mandiant reported that financially motivated threat group LightBasin (also tracked as UNC2891) deployed a previously unknown Oracle Solaris rootkit called Caketap in attacks linked to ATM cash-out fraud. The malware was installed on breached ATM switch servers and operated as a Unix kernel module, hiding files, processes, and network connections while hooking system functions to receive remote commands and maintain stealth on mission-critical banking infrastructure.
Investigators said Caketap intercepted card and PIN verification messages sent between ATM switch servers and payment hardware security modules, allowing fraudulent cards to be approved without disrupting legitimate customer transactions. The activity was tied to unauthorized cash withdrawals at several banks, and Mandiant said the group also used tools including Slapstick and TinyShell, underscoring its focus on poorly monitored Unix and Linux systems that support high-value financial operations.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
Mandiant said LightBasin was observed compromising managed service providers and victimizing their clients in 2020. This establishes earlier known activity by the financially motivated group before the ATM fraud operations described later.
Mandiant stated that LightBasin had recently been observed targeting telecom companies with custom implants. The report also noted the group continued deploying other tools such as Slapstick and Tinyshell in its operations.
Mandiant reported that LightBasin, also tracked as UNC2891, used the previously unknown Oracle Solaris rootkit Caketap on breached ATM switch servers to intercept and manipulate card and PIN verification traffic. Mandiant assessed the activity was part of a broader operation that enabled unauthorized cash withdrawals from ATM terminals at several banks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.