ATT&CKReferencesIntezer TeamTNT September 2020

Intezer TeamTNT September 2020

Fishbein, N. (2020, September 8). Attackers Abusing Legitimate Cloud Monitoring Tools to Conduct Cyber Attacks. Retrieved September 22, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1021.004
SSH
GroupTeamTNT

TeamTNT has used SSH to connect back to victim machines. TeamTNT has also used SSH to transfer tools and payloads onto victim hosts and execute them.

T1071.001
Web Protocols
GroupTeamTNT

TeamTNT has the `curl` command to send credentials over HTTP and the `curl` and `wget` commands to download new software. TeamTNT has also used a custom user agent HTTP header in shell scripts.

T1105
Ingress Tool Transfer
GroupTeamTNT

TeamTNT has the curl and wget commands as well as batch scripts to download new tools.

T1133
External Remote Services
GroupTeamTNT

TeamTNT has used open-source tools such as Weave Scope to target exposed Docker API ports and gain initial access to victim environments. TeamTNT has also targeted exposed kubelets for Kubernetes environments.

T1136.001
Local Account
GroupTeamTNT

TeamTNT has created local privileged users on victim machines.

T1610
Deploy Container
GroupTeamTNT

TeamTNT has deployed different types of containers into victim environments to facilitate execution. TeamTNT has also transferred cryptocurrency mining software to Kubernetes clusters discovered within local IP address ranges.

T1611
Escape to Host
GroupTeamTNT

TeamTNT has deployed privileged containers that mount the filesystem of victim machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.