Fiser, D. Oliveira, A. (n.d.). Tracking the Activities of TeamTNT A Closer Look at a Cloud-Focused Malicious Actor Group. Retrieved September 22, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1014 Rootkit |
GroupTeamTNT | TeamTNT has used rootkits such as the open-source Diamorphine rootkit and their custom bots to hide cryptocurrency mining activities on the machine. |
| T1016 System Network Configuration Discovery |
GroupTeamTNT | TeamTNT has enumerated the host machine’s IP address. |
| T1027.002 Software Packing |
GroupTeamTNT | TeamTNT has used UPX and Ezuri packer to pack its binaries. |
| T1027.013 Encrypted/Encoded File |
GroupTeamTNT | TeamTNT has encrypted its binaries via AES and encoded files using Base64. |
| T1049 System Network Connections Discovery |
GroupTeamTNT | TeamTNT has run |
| T1057 Process Discovery |
GroupTeamTNT | TeamTNT has searched for rival malware and removes it if found. TeamTNT has also searched for running processes containing the strings aliyun or liyun to identify machines running Alibaba Cloud Security tools. |
| T1059.004 Unix Shell |
GroupTeamTNT | TeamTNT has used shell scripts for execution. |
| T1070.003 Clear Command History |
GroupTeamTNT | TeamTNT has cleared command history with |
| T1071 Application Layer Protocol |
GroupTeamTNT | TeamTNT has used an IRC bot for C2 communications. |
| T1071.001 Web Protocols |
GroupTeamTNT | TeamTNT has the `curl` command to send credentials over HTTP and the `curl` and `wget` commands to download new software. TeamTNT has also used a custom user agent HTTP header in shell scripts. |
| T1222.002 Linux and Mac Permissions |
GroupTeamTNT | TeamTNT has modified the permissions on binaries with |
| T1543.002 Systemd Service |
GroupTeamTNT | TeamTNT has established persistence through the creation of a cryptocurrency mining system service using |
| T1552.001 Credentials In Files |
GroupTeamTNT | TeamTNT has searched for unsecured AWS credentials and Docker API credentials. |
| T1552.004 Private Keys |
GroupTeamTNT | TeamTNT has searched for unsecured SSH keys. |
| T1552.005 Cloud Instance Metadata API |
GroupTeamTNT | TeamTNT has queried the AWS instance metadata service for credentials. |
| T1595.001 Scanning IP Blocks |
GroupTeamTNT | TeamTNT has scanned specific lists of target IP addresses. |
| T1595.002 Vulnerability Scanning |
GroupTeamTNT | TeamTNT has scanned for vulnerabilities in IoT devices and other related resources such as the Docker API. |
| T1610 Deploy Container |
GroupTeamTNT | TeamTNT has deployed different types of containers into victim environments to facilitate execution. TeamTNT has also transferred cryptocurrency mining software to Kubernetes clusters discovered within local IP address ranges. |
| T1613 Container and Resource Discovery |
GroupTeamTNT | TeamTNT has checked for running containers with |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.