Financially motivated threat operation UNC2891 has enlisted money mules, created cloned ATM cards, and managed a comprehensive withdrawal network in its attacks against a pair of Indonesian banks between 2022 and 2024, all of which involved the STEELCORGI packing tool, according to Infosecurity Magazine.Intrusions by UNC2891 also entailed the advanced CAKETAP rootkit, which allowed the evasion of ATM verification protocols, as well as TINYSHELL, SLAPSTICK, and SUN4ME backdoors for persistence, a report from Group-IB revealed. UNC2891 also harnessed encrypted HTTPS channels, OpenVPN communications, and DNS tunneling for redundancy, while ensuring untraceability via the MIGLOGCLEANER and LOGBLEACH tools. Such findings have prompted researchers to suggest that reduced corporate efforts to combat ATM-focused cybercrime were unwise."UNC2891 is proof that ATM threats did not disappear they simply evolved. Their resurgence, now enhanced by physical access vectors and deeply embedded tooling, suggests a new chapter in financial intrusions," said Group-IB.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
