AT&T Alien Labs. (2021, September 8). TeamTNT with new campaign aka Chimaera. Retrieved September 22, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1049 System Network Connections Discovery |
GroupTeamTNT | TeamTNT has run |
| T1059.001 PowerShell |
GroupTeamTNT | TeamTNT has executed PowerShell commands in batch scripts. |
| T1059.003 Windows Command Shell |
GroupTeamTNT | TeamTNT has used batch scripts to download tools and executing cryptocurrency miners. |
| T1070.004 File Deletion |
GroupTeamTNT | TeamTNT has used a payload that removes itself after running. TeamTNT also has deleted locally staged files for collecting credentials or scan results for local IP addresses after exfiltrating them. |
| T1082 System Information Discovery |
GroupTeamTNT | TeamTNT has searched for system version, architecture, and hostname information. |
| T1518.001 Security Software Discovery |
GroupTeamTNT | TeamTNT has searched for security products on infected machines. |
| T1543.003 Windows Service |
GroupTeamTNT | TeamTNT has used malware that adds cryptocurrency miners as a service. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupTeamTNT | TeamTNT has added batch scripts to the startup folder. |
| T1680 Local Storage Discovery |
GroupTeamTNT | TeamTNT has searched for disk partition and logical volume information. |
| T1685 Disable or Modify Tools |
GroupTeamTNT | TeamTNT has disabled and uninstalled security tools such as Alibaba, Tencent, and BMC cloud monitoring agents on cloud-based infrastructure. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.