A financially motivated cyber‑crime group dubbed UNC2891 has demonstrated a worrying blend of physical and network‑level intrusion techniques. According to Group‑IB and Mandiant reports highlighted by The Hacker News, the attackers physically connected a 4G‑equipped Raspberry Pi to an Automated Teller Machine (ATM) network and used it to establish a covert channel for future fraud. This novel attack illustrates how criminals are combining inexpensive hardware with sophisticated malware to compromise critical banking infrastructure.

Anatomy of the attack

The breach involved a cyber‑physical operation. An attacker gained access to a bank’s premises and plugged a Raspberry Pi, fitted with a 4G modem, into the same network switch as the ATM. Once connected, the device established an outbound command‑and‑control channel using a Dynamic DNS domain through a custom backdoor called TINYSHELL. This bypassed perimeter firewalls and allowed continuous remote access to the ATM network.

UNC2891, first documented by Mandiant in March 2022, is known for attacking ATM switching networks to perform fraudulent cash withdrawals. In this incident, the group attempted to deploy CAKETAP, a kernel rootkit that hides processes, files and network connections and can intercept and spoof card‑verification messages from hardware security modules. The objective is to modify ATM commands and authorise unauthorized withdrawals without detection. Although the campaign was disrupted before any money was stolen, Group‑IB noted that the attackers retained internal access via a backdoor on the bank’s mail server.

Technical sophistication

UNC2891’s tactics reveal deep expertise in Linux and Unix systems. Investigators found backdoors labelled “lightdm” on the bank’s network monitoring server that created active connections between the Raspberry Pi and the internal mail server. The crew also abused bind mounts – a Linux feature that maps directories to different locations in the filesystem – to hide the backdoor from process listings and avoid detection.

The group shares tactical overlaps with another actor known as UNC1945 (LightBasin), which previously compromised managed service providers and targeted financial and consulting firms. Both groups demonstrate a sophisticated understanding of financial networks and a willingness to combine hardware tampering with advanced malware.

Implications and recommendations

This incident underscores the need for banks and critical infrastructure providers to monitor both physical and digital attack vectors. Key takeaways include:

  • Physical security matters. Ensure that network hardware, ATMs and cable closets are secured against unauthorized access. Deploy surveillance and alarms around critical infrastructure.
  • Network segmentation. Isolate ATM networks from administrative and corporate systems to limit the impact of a breach.
  • Endpoint monitoring. Use anomaly detection to spot unusual devices (such as unknown Raspberry Pis) on the network. Implement hardware access controls that restrict new devices from automatically joining.
  • Kernel rootkit detection. Employ tools that monitor kernel modules and detect unauthorized modifications. Regularly audit servers for hidden backdoors and suspicious processes.
  • Incident response readiness. Even though the campaign was disrupted before fraudulent withdrawals occurred, the attackers maintained access via a mail server backdoor. This highlights the importance of conducting thorough post‑incident investigations to eradicate all traces of intrusion.

Please subscribe to the Newsletter so that you do not miss any critical update

Leave a Reply

Your email address will not be published. Required fields are marked *