Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

// request.cf · coarse context

A page that knows where it met you.

Only coarse request metadata is shown. This demo does not display or persist visitor IP addresses.

Country
US
Cloudflare location
CMH
Connection
HTTP/2
Language
Not provided

Ray ID: a24fe54f6cebfda9

Jump to content

// Workers AI · dad joke modeWhat did caketap say? Tap into cake.

From Wikipedia, the free encyclopedia

Caketap is a rootkit for Oracle Solaris discovered in the wild in 2022. Caketap was discovered by Mandiant when investigating an intrusion cluster by actor UNC2891 also known as LightBasin.[1]

History

[edit]

While Caketap was discovered in by 16 March 2022, it rose to prominence when it was used in a Raspberry Pi mediated penetration of an ATM Network, discovered by Group-IB in late July 2025.[2] Once again LightBasin were believed to be responsible.

Associated tools

[edit]

UNC2891 utilises several supporting tools: TinyShell, Slapstick, Steelcorgi, Steelhound, Winghook, Wingcrack, Binbash, Wiperight, Miglogcleaner, and the Sun4Me toolkit.

References

[edit]
  1. "Have Your Cake and Eat it Too? An Overview of UNC2891 | Mandiant". Google Cloud Blog. 16 March 2022. Retrieved 2 August 2025.
  2. "UNC2891 Bank Heist: Physical ATM Backdoor & Linux Forensic Evasion Evasion". 30 July 2025.[dead link]
[edit]