Kol, Roi. Morag, A. (2020, August 25). Deep Analysis of TeamTNT Techniques Using Container Images to Attack. Retrieved September 22, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
GroupTeamTNT | TeamTNT has encrypted its binaries via AES and encoded files using Base64. |
| T1098.004 SSH Authorized Keys |
GroupTeamTNT | TeamTNT has added RSA keys in |
| T1102 Web Service |
GroupTeamTNT | TeamTNT has leveraged iplogger.org to send collected data back to C2. |
| T1611 Escape to Host |
GroupTeamTNT | TeamTNT has deployed privileged containers that mount the filesystem of victim machine. |
| T1685.006 Clear Linux or Mac System Logs |
GroupTeamTNT | TeamTNT has removed system logs from |
| T1686 Disable or Modify System Firewall |
GroupTeamTNT | TeamTNT has disabled |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.