All threat actors

UNC2891

Alert me

A financially motivated actor active since at least 2017 that targets banks and ATM-processing environments. It compromises Unix, Linux, and Solaris systems with tools such as CAKETAP, SLAPSTICK, and TINYSHELL to manipulate payment infrastructure and enable fraudulent ATM withdrawals.

Create a free account to see the reports

Sign in or create a free account to see every report that names UNC2891.

Create free account