Real-world descriptions of how a group, tool or campaign used a technique.
56 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
GroupTeamTNT | TeamTNT has searched for services such as Alibaba Cloud Security's aliyun service and BMC Helix Cloud Security's bmc-agent service in order to disable them. |
| T1014 Rootkit |
GroupTeamTNT | TeamTNT has used rootkits such as the open-source Diamorphine rootkit and their custom bots to hide cryptocurrency mining activities on the machine. |
| T1016 System Network Configuration Discovery |
GroupTeamTNT | TeamTNT has enumerated the host machine’s IP address. |
| T1021.004 SSH |
GroupTeamTNT | TeamTNT has used SSH to connect back to victim machines. TeamTNT has also used SSH to transfer tools and payloads onto victim hosts and execute them. |
| T1027.002 Software Packing |
GroupTeamTNT | TeamTNT has used UPX and Ezuri packer to pack its binaries. |
| T1027.013 Encrypted/Encoded File |
GroupTeamTNT | TeamTNT has encrypted its binaries via AES and encoded files using Base64. |
| T1036 Masquerading |
GroupTeamTNT | TeamTNT has disguised their scripts with docker-related file names. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupTeamTNT | TeamTNT has replaced .dockerd and .dockerenv with their own scripts and cryptocurrency mining software. |
| T1046 Network Service Discovery |
GroupTeamTNT | TeamTNT has used masscan to search for open Docker API ports and Kubernetes clusters. TeamTNT has also used malware that utilizes zmap and zgrab to search for vulnerable services in cloud environments. |
| T1048 Exfiltration Over Alternative Protocol |
GroupTeamTNT | TeamTNT has sent locally staged files with collected credentials to C2 servers using cURL. |
| T1049 System Network Connections Discovery |
GroupTeamTNT | TeamTNT has run |
| T1057 Process Discovery |
GroupTeamTNT | TeamTNT has searched for rival malware and removes it if found. TeamTNT has also searched for running processes containing the strings aliyun or liyun to identify machines running Alibaba Cloud Security tools. |
| T1059.001 PowerShell |
GroupTeamTNT | TeamTNT has executed PowerShell commands in batch scripts. |
| T1059.003 Windows Command Shell |
GroupTeamTNT | TeamTNT has used batch scripts to download tools and executing cryptocurrency miners. |
| T1059.004 Unix Shell |
GroupTeamTNT | TeamTNT has used shell scripts for execution. |
| T1059.009 Cloud API |
GroupTeamTNT | TeamTNT has leveraged AWS CLI to enumerate cloud environments with compromised credentials. |
| T1059.013 Container CLI/API |
GroupTeamTNT | TeamTNT targeted misconfigured containers and used container CLI tools. |
| T1070.003 Clear Command History |
GroupTeamTNT | TeamTNT has cleared command history with |
| T1070.004 File Deletion |
GroupTeamTNT | TeamTNT has used a payload that removes itself after running. TeamTNT also has deleted locally staged files for collecting credentials or scan results for local IP addresses after exfiltrating them. |
| T1071 Application Layer Protocol |
GroupTeamTNT | TeamTNT has used an IRC bot for C2 communications. |
| T1071.001 Web Protocols |
GroupTeamTNT | TeamTNT has the `curl` command to send credentials over HTTP and the `curl` and `wget` commands to download new software. TeamTNT has also used a custom user agent HTTP header in shell scripts. |
| T1074.001 Local Data Staging |
GroupTeamTNT | TeamTNT has aggregated collected credentials in text files before exfiltrating. |
| T1082 System Information Discovery |
GroupTeamTNT | TeamTNT has searched for system version, architecture, and hostname information. |
| T1083 File and Directory Discovery |
GroupTeamTNT | TeamTNT has used a script that checks `/proc/*/environ` for environment variables related to AWS. |
| T1098.004 SSH Authorized Keys |
GroupTeamTNT | TeamTNT has added RSA keys in |
| T1102 Web Service |
GroupTeamTNT | TeamTNT has leveraged iplogger.org to send collected data back to C2. |
| T1105 Ingress Tool Transfer |
GroupTeamTNT | TeamTNT has the |
| T1120 Peripheral Device Discovery |
GroupTeamTNT | TeamTNT has searched for attached VGA devices using lspci. |
| T1133 External Remote Services |
GroupTeamTNT | TeamTNT has used open-source tools such as Weave Scope to target exposed Docker API ports and gain initial access to victim environments. TeamTNT has also targeted exposed kubelets for Kubernetes environments. |
| T1136.001 Local Account |
GroupTeamTNT | TeamTNT has created local privileged users on victim machines. |
| T1140 Deobfuscate/Decode Files or Information |
GroupTeamTNT | TeamTNT has used a script that decodes a Base64-encoded version of WeaveWorks Scope. |
| T1204.003 Malicious Image |
GroupTeamTNT | TeamTNT has relied on users to download and execute malicious Docker images. |
| T1219 Remote Access Tools |
GroupTeamTNT | TeamTNT has established tmate sessions for C2 communications. |
| T1222.002 Linux and Mac Permissions |
GroupTeamTNT | TeamTNT has modified the permissions on binaries with |
| T1496.001 Compute Hijacking |
GroupTeamTNT | TeamTNT has deployed XMRig Docker images to mine cryptocurrency. TeamTNT has also infected Docker containers and Kubernetes clusters with XMRig, and used RainbowMiner and lolMiner for mining cryptocurrency. |
| T1518.001 Security Software Discovery |
GroupTeamTNT | TeamTNT has searched for security products on infected machines. |
| T1543.002 Systemd Service |
GroupTeamTNT | TeamTNT has established persistence through the creation of a cryptocurrency mining system service using |
| T1543.003 Windows Service |
GroupTeamTNT | TeamTNT has used malware that adds cryptocurrency miners as a service. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupTeamTNT | TeamTNT has added batch scripts to the startup folder. |
| T1552.001 Credentials In Files |
GroupTeamTNT | TeamTNT has searched for unsecured AWS credentials and Docker API credentials. |
| T1552.004 Private Keys |
GroupTeamTNT | TeamTNT has searched for unsecured SSH keys. |
| T1552.005 Cloud Instance Metadata API |
GroupTeamTNT | TeamTNT has queried the AWS instance metadata service for credentials. |
| T1569.003 Systemctl |
GroupTeamTNT | TeamTNT has created system services to execute cryptocurrency mining software. |
| T1583.001 Domains |
GroupTeamTNT | TeamTNT has obtained domains to host their payloads. |
| T1587.001 Malware |
GroupTeamTNT | |
| T1595.001 Scanning IP Blocks |
GroupTeamTNT | TeamTNT has scanned specific lists of target IP addresses. |
| T1595.002 Vulnerability Scanning |
GroupTeamTNT | TeamTNT has scanned for vulnerabilities in IoT devices and other related resources such as the Docker API. |
| T1608.001 Upload Malware |
GroupTeamTNT | TeamTNT has uploaded backdoored Docker images to Docker Hub. |
| T1609 Container Administration Command |
GroupTeamTNT | TeamTNT executed Hildegard through the kubelet API run command and by executing commands on running containers. |
| T1610 Deploy Container |
GroupTeamTNT | TeamTNT has deployed different types of containers into victim environments to facilitate execution. TeamTNT has also transferred cryptocurrency mining software to Kubernetes clusters discovered within local IP address ranges. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.