ATT&CKReferencesATT TeamTNT Chimaera September 2020

ATT TeamTNT Chimaera September 2020

AT&T Alien Labs. (2021, September 8). TeamTNT with new campaign aka Chimaera. Retrieved September 22, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1049
System Network Connections Discovery
GroupTeamTNT

TeamTNT has run netstat -anp to search for rival malware connections. TeamTNT has also used `libprocesshider` to modify /etc/ld.so.preload.

T1059.001
PowerShell
GroupTeamTNT

TeamTNT has executed PowerShell commands in batch scripts.

T1059.003
Windows Command Shell
GroupTeamTNT

TeamTNT has used batch scripts to download tools and executing cryptocurrency miners.

T1070.004
File Deletion
GroupTeamTNT

TeamTNT has used a payload that removes itself after running. TeamTNT also has deleted locally staged files for collecting credentials or scan results for local IP addresses after exfiltrating them.

T1082
System Information Discovery
GroupTeamTNT

TeamTNT has searched for system version, architecture, and hostname information.

T1518.001
Security Software Discovery
GroupTeamTNT

TeamTNT has searched for security products on infected machines.

T1543.003
Windows Service
GroupTeamTNT

TeamTNT has used malware that adds cryptocurrency miners as a service.

T1547.001
Registry Run Keys / Startup Folder
GroupTeamTNT

TeamTNT has added batch scripts to the startup folder.

T1680
Local Storage Discovery
GroupTeamTNT

TeamTNT has searched for disk partition and logical volume information.

T1685
Disable or Modify Tools
GroupTeamTNT

TeamTNT has disabled and uninstalled security tools such as Alibaba, Tencent, and BMC cloud monitoring agents on cloud-based infrastructure.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.