Hackers Plant Raspberry Pi Inside ATM Networks to Steal Millions – Here’s How It Happened

Listen to this Post

Featured Image
Inside the Most Shocking Bank Cyberattack Using a Raspberry Pi

A high-stakes cyber heist has come to light, revealing how a financially driven hacking group known as UNC2891 infiltrated ATM networks using a \$35 Raspberry Pi equipped with a 4G modem. This small but powerful computer was covertly installed inside a bank’s physical infrastructure, granting the attackers remote access to sensitive ATM switching networks.

Cybersecurity firm Group-IB uncovered the plot, describing how the attackers connected the Raspberry Pi directly to a network switch shared with ATMs, bypassing traditional cybersecurity defenses. Using a backdoor known as TINYSHELL and Dynamic DNS, the attackers maintained persistent remote control over the bank’s systems. Their main goal? Unauthorized ATM cash withdrawals using fraudulent cards.

Though the campaign was disrupted before serious damage occurred, the attempt highlights a worrying trend: cyber-physical attacks combining on-site access with digital backdoors. The operation used a sophisticated rootkit called CAKETAP, capable of spoofing PIN verification messages and evading detection. UNC2891 also appears to share tactics with UNC1945 (LightBasin), a group known for attacking the financial sector.

Let’s break down what this means and how it could impact the future of ATM and bank security.

🧠 Full Breakdown of the Covert Attack

🚨 Covert Hardware Installation

UNC2891 physically planted a Raspberry Pi into the ATM network, connecting it to the same switch as the ATMs. This hardware contained a 4G modem, enabling remote access via mobile data and bypassing any reliance on internal Wi-Fi or ethernet monitoring.

🕵️ Sophisticated Malware Deployment

The group used a malware backdoor named TINYSHELL, configured to communicate with a Dynamic DNS domain for outbound command-and-control (C2). This allowed them to control the Pi without triggering perimeter firewalls or standard intrusion detection systems.

🧬 Use of Rootkit: CAKETAP

At the heart of the attack lies CAKETAP, a kernel-level rootkit designed to hide files, processes, and spoof security module responses. It’s tailored for ATM switching networks, which are responsible for processing transaction messages and card verification. This tool essentially gave them control to fake card approvals.

🔍 Persistence Beyond Discovery

Even after the Raspberry Pi was removed, Group-IB’s research revealed that the attackers still maintained internal access via a backdoor on the bank’s mail server. This enabled continued C2 operations even after initial hardware was extracted.

🧩 Ties to UNC1945 (LightBasin)

UNC2891 shares overlaps with UNC1945, a group known for attacking managed service providers and high-profile finance targets. These groups are highly skilled in Unix/Linux environments and specialize in staying undetected for long periods.

🛡️ Evasion Techniques

UNC2891 used bind mounts and hidden processes to camouflage their malware, making detection extremely difficult. These techniques allowed them to blend their malware into normal-looking system activity.

💬 What Undercode Say:

Deep Analysis of UNC2891’s Attack Tactics

UNC2891’s latest campaign reflects the evolution of cybercrime from software-based intrusions to hybrid cyber-physical attacks. By combining physical access with advanced malware engineering, the group demonstrated a dangerous capability to breach what many believe to be secure banking environments.

Unlike many threat actors that rely solely on phishing or remote software exploits, UNC2891 directly breached the physical network perimeter, highlighting a significant vulnerability in on-site IT asset management. Banks and financial institutions often rely on air-gapped assumptions – i.e., systems that aren’t supposed to connect to the outside world. UNC2891 proved otherwise.

The use of Dynamic DNS and mobile data is a critical innovation. It eliminates reliance on corporate internet infrastructure, allowing attackers to fully control the malware over a separate network path. This is a major blind spot for traditional intrusion detection systems.

Furthermore, the deployment of CAKETAP on ATM switching servers allowed them to spoof and intercept Hardware Security Module (HSM) responses, which are normally used to verify sensitive data like PINs. By hijacking these messages, UNC2891 could perform unauthorized cash-outs without triggering red flags.

The discovery of persistent backdoors on both monitoring and mail servers shows the group’s multi-layered fallback strategy. Even after detection, they had tools in place to re-enter or remain active inside the system. These are signs of a military-grade cyber strategy, not your average cybercriminal behavior.

What makes this attack even more alarming is its cost-effectiveness. A Raspberry Pi and 4G modem are cheap and easy to acquire, yet this combo nearly resulted in multi-million dollar ATM fraud.

Banks need to rethink their physical security and IT integration. Having isolated systems is no longer enough. Every physical access point must now be considered a potential entry vector for cyberattacks.

In conclusion, UNC2891’s campaign demonstrates the dangerous synergy between physical and cyber threats. It’s a wake-up call for the entire financial sector.

✅ Fact Checker Results

✅ Confirmed: Group-IB verified the attack used Raspberry Pi with a 4G modem.
✅ Verified: CAKETAP rootkit was used to spoof ATM verification processes.
✅ Undisputed: Attack was disrupted before major financial losses occurred.

🔮 Prediction 🔥

Cybercriminals will increasingly blend physical and digital tactics in future heists. Expect more incidents where attackers physically implant devices inside secure networks to bypass digital-only defenses. ATM systems, industrial IoT, and SCADA networks are top targets for this strategy. Banks must evolve their security posture by integrating physical access controls with digital threat monitoring to prevent hybrid attacks like this from succeeding again.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: thehackernews.com
Extra Source Hub:
https://www.reddit.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon