ATT&CKReferencesAqua TeamTNT August 2020

Aqua TeamTNT August 2020

Kol, Roi. Morag, A. (2020, August 25). Deep Analysis of TeamTNT Techniques Using Container Images to Attack. Retrieved September 22, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
GroupTeamTNT

TeamTNT has encrypted its binaries via AES and encoded files using Base64.

T1098.004
SSH Authorized Keys
GroupTeamTNT

TeamTNT has added RSA keys in authorized_keys.

T1102
Web Service
GroupTeamTNT

TeamTNT has leveraged iplogger.org to send collected data back to C2.

T1611
Escape to Host
GroupTeamTNT

TeamTNT has deployed privileged containers that mount the filesystem of victim machine.

T1685.006
Clear Linux or Mac System Logs
GroupTeamTNT

TeamTNT has removed system logs from /var/log/syslog.

T1686
Disable or Modify System Firewall
GroupTeamTNT

TeamTNT has disabled iptables.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.