ATT&CKReferencesTrend Micro TeamTNT

Trend Micro TeamTNT

Fiser, D. Oliveira, A. (n.d.). Tracking the Activities of TeamTNT A Closer Look at a Cloud-Focused Malicious Actor Group. Retrieved September 22, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1014
Rootkit
GroupTeamTNT

TeamTNT has used rootkits such as the open-source Diamorphine rootkit and their custom bots to hide cryptocurrency mining activities on the machine.

T1016
System Network Configuration Discovery
GroupTeamTNT

TeamTNT has enumerated the host machine’s IP address.

T1027.002
Software Packing
GroupTeamTNT

TeamTNT has used UPX and Ezuri packer to pack its binaries.

T1027.013
Encrypted/Encoded File
GroupTeamTNT

TeamTNT has encrypted its binaries via AES and encoded files using Base64.

T1049
System Network Connections Discovery
GroupTeamTNT

TeamTNT has run netstat -anp to search for rival malware connections. TeamTNT has also used `libprocesshider` to modify /etc/ld.so.preload.

T1057
Process Discovery
GroupTeamTNT

TeamTNT has searched for rival malware and removes it if found. TeamTNT has also searched for running processes containing the strings aliyun or liyun to identify machines running Alibaba Cloud Security tools.

T1059.004
Unix Shell
GroupTeamTNT

TeamTNT has used shell scripts for execution.

T1070.003
Clear Command History
GroupTeamTNT

TeamTNT has cleared command history with history -c.

T1071
Application Layer Protocol
GroupTeamTNT

TeamTNT has used an IRC bot for C2 communications.

T1071.001
Web Protocols
GroupTeamTNT

TeamTNT has the `curl` command to send credentials over HTTP and the `curl` and `wget` commands to download new software. TeamTNT has also used a custom user agent HTTP header in shell scripts.

T1222.002
Linux and Mac Permissions
GroupTeamTNT

TeamTNT has modified the permissions on binaries with chattr.

T1543.002
Systemd Service
GroupTeamTNT

TeamTNT has established persistence through the creation of a cryptocurrency mining system service using systemctl.

T1552.001
Credentials In Files
GroupTeamTNT

TeamTNT has searched for unsecured AWS credentials and Docker API credentials.

T1552.004
Private Keys
GroupTeamTNT

TeamTNT has searched for unsecured SSH keys.

T1552.005
Cloud Instance Metadata API
GroupTeamTNT

TeamTNT has queried the AWS instance metadata service for credentials.

T1595.001
Scanning IP Blocks
GroupTeamTNT

TeamTNT has scanned specific lists of target IP addresses.

T1595.002
Vulnerability Scanning
GroupTeamTNT

TeamTNT has scanned for vulnerabilities in IoT devices and other related resources such as the Docker API.

T1610
Deploy Container
GroupTeamTNT

TeamTNT has deployed different types of containers into victim environments to facilitate execution. TeamTNT has also transferred cryptocurrency mining software to Kubernetes clusters discovered within local IP address ranges.

T1613
Container and Resource Discovery
GroupTeamTNT

TeamTNT has checked for running containers with docker ps and for specific container names with docker inspect. TeamTNT has also searched for Kubernetes pods running in a local network.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.