logo

LightBasin__2022__Mandiant_An-Overview-of-UNC2891_03-16-2022.pdf

ID: a31c469b-b241-4e3f-8563-2dd7515c0ac0

STIX ID: report--a31c469b-b241-4e3f-8563-2dd7515c0ac0

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2022-03-22

Last Modified Date: 2022-03-22

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Mandiant documents UNC2891, a sophisticated, financially motivated threat cluster that targeted Unix/Linux (notably Oracle Solaris) infrastructure using backdoors (TINYSHELL, SLAPSTICK), environment-keyed droppers (STEELHOUND/STEELCORGI), a Solaris kernel rootkit (CAKETAP) capable of hiding artifacts and manipulating ATM switch messages to enable fraudulent withdrawals, plus keyloggers and log-wiping utilities; the report includes technical TTPs, YARA rules, and indicators to support detection and response.