About
UNC2891 is a financially motivated threat actor active since at least November 2017, known for its advanced intrusions targeting banking infrastructure. The group possesses deep technical expertise in Linux, Unix, and Oracle Solaris environments, and employs a bespoke malware arsenal that includes tools like CAKETAP, TINYSHELL, and SLAPSTICK.
Group-IB was the first to uncover that UNC2891 had physically installed a Raspberry Pi device inside a bank’s internal network—connecting it to the same switch as an ATM — and used a 4G modem to establish remote access. This unprecedented tactic allowed the attackers to bypass perimeter defenses entirely. UNC2891 also leveraged anti-forensics techniques such as Linux bind mount abuse (MITRE ATT&CK T1564.013) to conceal their activity, enabling stealthy lateral movement and persistent access to critical systems, including ATM switching servers.