Hackers Use Raspberry Pi to Infiltrate Bank ATM Network
2025-08-01

Security firm Group-IB revealed a network attack targeting bank ATMs. Attackers used physical access to install a Raspberry Pi device connected to the ATM network switch, gaining access via a 4G modem. To maintain persistence, they compromised a mail server and cleverly used the bank's monitoring server as an intermediary to communicate with the Raspberry Pi and mail server backdoor. The attackers disguised the backdoor process to mimic the legitimate LightDM process, evading detection. Group-IB researchers uncovered this unusual activity and prevented the attackers from deploying the CakeTap backdoor.
Tech