Fishbein, N. (2020, September 8). Attackers Abusing Legitimate Cloud Monitoring Tools to Conduct Cyber Attacks. Retrieved September 22, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.004 SSH |
GroupTeamTNT | TeamTNT has used SSH to connect back to victim machines. TeamTNT has also used SSH to transfer tools and payloads onto victim hosts and execute them. |
| T1071.001 Web Protocols |
GroupTeamTNT | TeamTNT has the `curl` command to send credentials over HTTP and the `curl` and `wget` commands to download new software. TeamTNT has also used a custom user agent HTTP header in shell scripts. |
| T1105 Ingress Tool Transfer |
GroupTeamTNT | TeamTNT has the |
| T1133 External Remote Services |
GroupTeamTNT | TeamTNT has used open-source tools such as Weave Scope to target exposed Docker API ports and gain initial access to victim environments. TeamTNT has also targeted exposed kubelets for Kubernetes environments. |
| T1136.001 Local Account |
GroupTeamTNT | TeamTNT has created local privileged users on victim machines. |
| T1610 Deploy Container |
GroupTeamTNT | TeamTNT has deployed different types of containers into victim environments to facilitate execution. TeamTNT has also transferred cryptocurrency mining software to Kubernetes clusters discovered within local IP address ranges. |
| T1611 Escape to Host |
GroupTeamTNT | TeamTNT has deployed privileged containers that mount the filesystem of victim machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.