TeamTNT

G0139

Threat group.View on attack.mitre.org

About this group

TeamTNT is a threat group that has primarily targeted cloud and containerized environments. The group as been active since at least October 2019 and has mainly focused its efforts on leveraging cloud and container resources to deploy cryptocurrency miners in victim environments.

Techniques used56

Procedure examples56

TechniqueProcedure example
T1007
System Service Discovery

TeamTNT has searched for services such as Alibaba Cloud Security's aliyun service and BMC Helix Cloud Security's bmc-agent service in order to disable them.

T1014
Rootkit

TeamTNT has used rootkits such as the open-source Diamorphine rootkit and their custom bots to hide cryptocurrency mining activities on the machine.

T1016
System Network Configuration Discovery

TeamTNT has enumerated the host machine’s IP address.

T1021.004
SSH

TeamTNT has used SSH to connect back to victim machines. TeamTNT has also used SSH to transfer tools and payloads onto victim hosts and execute them.

T1027.002
Software Packing

TeamTNT has used UPX and Ezuri packer to pack its binaries.

T1027.013
Encrypted/Encoded File

TeamTNT has encrypted its binaries via AES and encoded files using Base64.

T1036
Masquerading

TeamTNT has disguised their scripts with docker-related file names.

T1036.005
Match Legitimate Resource Name or Location

TeamTNT has replaced .dockerd and .dockerenv with their own scripts and cryptocurrency mining software.

T1046
Network Service Discovery

TeamTNT has used masscan to search for open Docker API ports and Kubernetes clusters. TeamTNT has also used malware that utilizes zmap and zgrab to search for vulnerable services in cloud environments.

T1048
Exfiltration Over Alternative Protocol

TeamTNT has sent locally staged files with collected credentials to C2 servers using cURL.

T1049
System Network Connections Discovery

TeamTNT has run netstat -anp to search for rival malware connections. TeamTNT has also used `libprocesshider` to modify /etc/ld.so.preload.

T1057
Process Discovery

TeamTNT has searched for rival malware and removes it if found. TeamTNT has also searched for running processes containing the strings aliyun or liyun to identify machines running Alibaba Cloud Security tools.

T1059.001
PowerShell

TeamTNT has executed PowerShell commands in batch scripts.

T1059.003
Windows Command Shell

TeamTNT has used batch scripts to download tools and executing cryptocurrency miners.

T1059.004
Unix Shell

TeamTNT has used shell scripts for execution.

View all 56 procedure examples

Software4

Campaigns0

None recorded.

References9

  1. ATT TeamTNT Chimaera September 2020 Open source
    AT&T Alien Labs. (2021, September 8). TeamTNT with new campaign aka Chimaera. Retrieved September 22, 2021.
  2. Aqua TeamTNT August 2020 Open source
    Kol, Roi. Morag, A. (2020, August 25). Deep Analysis of TeamTNT Techniques Using Container Images to Attack. Retrieved September 22, 2021.
  3. Cado Security TeamTNT Worm August 2020 Open source
    Cado Security. (2020, August 16). Team TNT – The First Crypto-Mining Worm to Steal AWS Credentials. Retrieved September 22, 2021.
  4. Intezer TeamTNT Explosion September 2021 Open source
    Intezer. (2021, September 1). TeamTNT Cryptomining Explosion. Retrieved October 15, 2021.
  5. Intezer TeamTNT September 2020 Open source
    Fishbein, N. (2020, September 8). Attackers Abusing Legitimate Cloud Monitoring Tools to Conduct Cyber Attacks. Retrieved September 22, 2021.
  6. Lacework TeamTNT May 2021 Open source
    Stroud, J. (2021, May 25). Taking TeamTNT's Docker Images Offline. Retrieved September 16, 2024.
  7. Palo Alto Black-T October 2020 Open source
    Quist, N. (2020, October 5). Black-T: New Cryptojacking Variant from TeamTNT. Retrieved September 22, 2021.
  8. Trend Micro TeamTNT Open source
    Fiser, D. Oliveira, A. (n.d.). Tracking the Activities of TeamTNT A Closer Look at a Cloud-Focused Malicious Actor Group. Retrieved September 22, 2021.
  9. Unit 42 Hildegard Malware Open source
    Chen, J. et al. (2021, February 3). Hildegard: New TeamTNT Cryptojacking Malware Targeting Kubernetes. Retrieved April 5, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.