ATT&CKReferencesUnit 42 Hildegard Malware

Unit 42 Hildegard Malware

Chen, J. et al. (2021, February 3). Hildegard: New TeamTNT Cryptojacking Malware Targeting Kubernetes. Retrieved April 5, 2021.

Open the source

Techniques3

Groups1

Software1

Campaigns0

None recorded.

Procedure examples32

TechniqueUsed byProcedure example
T1014
Rootkit
MalwareHildegard

Hildegard has modified /etc/ld.so.preload to overwrite readdir() and readdir64().

T1027.002
Software Packing
MalwareHildegard

Hildegard has packed ELF files into other binaries.

T1027.013
Encrypted/Encoded File
MalwareHildegard

Hildegard has encrypted an ELF file.

T1036.004
Masquerade Task or Service
MalwareHildegard

Hildegard has disguised itself as a known Linux process.

T1046
Network Service Discovery
MalwareHildegard

Hildegard has used masscan to look for kubelets in the internal Kubernetes network.

T1046
Network Service Discovery
GroupTeamTNT

TeamTNT has used masscan to search for open Docker API ports and Kubernetes clusters. TeamTNT has also used malware that utilizes zmap and zgrab to search for vulnerable services in cloud environments.

T1059.004
Unix Shell
MalwareHildegard

Hildegard has used shell scripts for execution.

T1068
Exploitation for Privilege Escalation
MalwareHildegard

Hildegard has used the BOtB tool which exploits CVE-2019-5736.

T1070.003
Clear Command History
MalwareHildegard

Hildegard has used history -c to clear script shell logs.

T1070.004
File Deletion
MalwareHildegard

Hildegard has deleted scripts after execution.

T1071
Application Layer Protocol
MalwareHildegard

Hildegard has used an IRC channel for C2 communications.

T1082
System Information Discovery
MalwareHildegard

Hildegard has collected the host's OS, CPU, and memory information.

T1102
Web Service
MalwareHildegard

Hildegard has downloaded scripts from GitHub.

T1105
Ingress Tool Transfer
MalwareHildegard

Hildegard has downloaded additional scripts that build and run Monero cryptocurrency miners.

T1133
External Remote Services
GroupTeamTNT

TeamTNT has used open-source tools such as Weave Scope to target exposed Docker API ports and gain initial access to victim environments. TeamTNT has also targeted exposed kubelets for Kubernetes environments.

T1133
External Remote Services
MalwareHildegard

Hildegard was executed through an unsecure kubelet that allowed anonymous access to the victim environment.

T1136.001
Local Account
MalwareHildegard

Hildegard has created a user named “monerodaemon”.

T1140
Deobfuscate/Decode Files or Information
MalwareHildegard

Hildegard has decrypted ELF files with AES.

T1219
Remote Access Tools
GroupTeamTNT

TeamTNT has established tmate sessions for C2 communications.

T1219
Remote Access Tools
MalwareHildegard

Hildegard has established tmate sessions for C2 communications.

T1496.001
Compute Hijacking
MalwareHildegard

Hildegard has used xmrig to mine cryptocurrency.

T1543.002
Systemd Service
MalwareHildegard

Hildegard has started a monero service.

T1552.001
Credentials In Files
MalwareHildegard

Hildegard has searched for SSH keys, Docker credentials, and Kubernetes service tokens.

T1552.004
Private Keys
MalwareHildegard

Hildegard has searched for private keys in .ssh.

T1552.005
Cloud Instance Metadata API
MalwareHildegard

Hildegard has queried the Cloud Instance Metadata API for cloud credentials.

T1574.006
Dynamic Linker Hijacking
MalwareHildegard

Hildegard has modified /etc/ld.so.preload to intercept shared library import functions.

T1587.001
Malware
GroupTeamTNT

TeamTNT has developed custom malware such as Hildegard.

T1609
Container Administration Command
GroupTeamTNT

TeamTNT executed Hildegard through the kubelet API run command and by executing commands on running containers.

T1609
Container Administration Command
MalwareHildegard

Hildegard was executed through the kubelet API run command and by executing commands on running containers.

T1611
Escape to Host
MalwareHildegard

Hildegard has used the BOtB tool that can break out of containers.

T1613
Container and Resource Discovery
MalwareHildegard

Hildegard has used masscan to search for kubelets and the kubelet API for additional running containers.

T1685
Disable or Modify Tools
MalwareHildegard

Hildegard has modified DNS resolvers to evade DNS monitoring tools.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.