Threat group.View on attack.mitre.org
TeamTNT is a threat group that has primarily targeted cloud and containerized environments. The group as been active since at least October 2019 and has mainly focused its efforts on leveraging cloud and container resources to deploy cryptocurrency miners in victim environments.
| Technique | Procedure example |
|---|---|
| T1007 System Service Discovery |
TeamTNT has searched for services such as Alibaba Cloud Security's aliyun service and BMC Helix Cloud Security's bmc-agent service in order to disable them. |
| T1014 Rootkit |
TeamTNT has used rootkits such as the open-source Diamorphine rootkit and their custom bots to hide cryptocurrency mining activities on the machine. |
| T1016 System Network Configuration Discovery |
TeamTNT has enumerated the host machine’s IP address. |
| T1021.004 SSH |
TeamTNT has used SSH to connect back to victim machines. TeamTNT has also used SSH to transfer tools and payloads onto victim hosts and execute them. |
| T1027.002 Software Packing |
TeamTNT has used UPX and Ezuri packer to pack its binaries. |
| T1027.013 Encrypted/Encoded File |
TeamTNT has encrypted its binaries via AES and encoded files using Base64. |
| T1036 Masquerading |
TeamTNT has disguised their scripts with docker-related file names. |
| T1036.005 Match Legitimate Resource Name or Location |
TeamTNT has replaced .dockerd and .dockerenv with their own scripts and cryptocurrency mining software. |
| T1046 Network Service Discovery |
TeamTNT has used masscan to search for open Docker API ports and Kubernetes clusters. TeamTNT has also used malware that utilizes zmap and zgrab to search for vulnerable services in cloud environments. |
| T1048 Exfiltration Over Alternative Protocol |
TeamTNT has sent locally staged files with collected credentials to C2 servers using cURL. |
| T1049 System Network Connections Discovery |
TeamTNT has run |
| T1057 Process Discovery |
TeamTNT has searched for rival malware and removes it if found. TeamTNT has also searched for running processes containing the strings aliyun or liyun to identify machines running Alibaba Cloud Security tools. |
| T1059.001 PowerShell |
TeamTNT has executed PowerShell commands in batch scripts. |
| T1059.003 Windows Command Shell |
TeamTNT has used batch scripts to download tools and executing cryptocurrency miners. |
| T1059.004 Unix Shell |
TeamTNT has used shell scripts for execution. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.