Chen, J. et al. (2021, February 3). Hildegard: New TeamTNT Cryptojacking Malware Targeting Kubernetes. Retrieved April 5, 2021.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1014 Rootkit |
MalwareHildegard | Hildegard has modified /etc/ld.so.preload to overwrite readdir() and readdir64(). |
| T1027.002 Software Packing |
MalwareHildegard | Hildegard has packed ELF files into other binaries. |
| T1027.013 Encrypted/Encoded File |
MalwareHildegard | Hildegard has encrypted an ELF file. |
| T1036.004 Masquerade Task or Service |
MalwareHildegard | Hildegard has disguised itself as a known Linux process. |
| T1046 Network Service Discovery |
MalwareHildegard | Hildegard has used masscan to look for kubelets in the internal Kubernetes network. |
| T1046 Network Service Discovery |
GroupTeamTNT | TeamTNT has used masscan to search for open Docker API ports and Kubernetes clusters. TeamTNT has also used malware that utilizes zmap and zgrab to search for vulnerable services in cloud environments. |
| T1059.004 Unix Shell |
MalwareHildegard | Hildegard has used shell scripts for execution. |
| T1068 Exploitation for Privilege Escalation |
MalwareHildegard | Hildegard has used the BOtB tool which exploits CVE-2019-5736. |
| T1070.003 Clear Command History |
MalwareHildegard | Hildegard has used history -c to clear script shell logs. |
| T1070.004 File Deletion |
MalwareHildegard | Hildegard has deleted scripts after execution. |
| T1071 Application Layer Protocol |
MalwareHildegard | Hildegard has used an IRC channel for C2 communications. |
| T1082 System Information Discovery |
MalwareHildegard | Hildegard has collected the host's OS, CPU, and memory information. |
| T1102 Web Service |
MalwareHildegard | Hildegard has downloaded scripts from GitHub. |
| T1105 Ingress Tool Transfer |
MalwareHildegard | Hildegard has downloaded additional scripts that build and run Monero cryptocurrency miners. |
| T1133 External Remote Services |
GroupTeamTNT | TeamTNT has used open-source tools such as Weave Scope to target exposed Docker API ports and gain initial access to victim environments. TeamTNT has also targeted exposed kubelets for Kubernetes environments. |
| T1133 External Remote Services |
MalwareHildegard | Hildegard was executed through an unsecure kubelet that allowed anonymous access to the victim environment. |
| T1136.001 Local Account |
MalwareHildegard | Hildegard has created a user named “monerodaemon”. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareHildegard | Hildegard has decrypted ELF files with AES. |
| T1219 Remote Access Tools |
GroupTeamTNT | TeamTNT has established tmate sessions for C2 communications. |
| T1219 Remote Access Tools |
MalwareHildegard | Hildegard has established tmate sessions for C2 communications. |
| T1496.001 Compute Hijacking |
MalwareHildegard | Hildegard has used xmrig to mine cryptocurrency. |
| T1543.002 Systemd Service |
MalwareHildegard | Hildegard has started a monero service. |
| T1552.001 Credentials In Files |
MalwareHildegard | Hildegard has searched for SSH keys, Docker credentials, and Kubernetes service tokens. |
| T1552.004 Private Keys |
MalwareHildegard | Hildegard has searched for private keys in .ssh. |
| T1552.005 Cloud Instance Metadata API |
MalwareHildegard | Hildegard has queried the Cloud Instance Metadata API for cloud credentials. |
| T1574.006 Dynamic Linker Hijacking |
MalwareHildegard | Hildegard has modified /etc/ld.so.preload to intercept shared library import functions. |
| T1587.001 Malware |
GroupTeamTNT | |
| T1609 Container Administration Command |
GroupTeamTNT | TeamTNT executed Hildegard through the kubelet API run command and by executing commands on running containers. |
| T1609 Container Administration Command |
MalwareHildegard | Hildegard was executed through the kubelet API run command and by executing commands on running containers. |
| T1611 Escape to Host |
MalwareHildegard | Hildegard has used the BOtB tool that can break out of containers. |
| T1613 Container and Resource Discovery |
MalwareHildegard | Hildegard has used masscan to search for kubelets and the kubelet API for additional running containers. |
| T1685 Disable or Modify Tools |
MalwareHildegard | Hildegard has modified DNS resolvers to evade DNS monitoring tools. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.