Hildegard

S0601

Malware.View on attack.mitre.org

About this malware

Hildegard is malware that targets misconfigured kubelets for initial access and runs cryptocurrency miner operations. The malware was first observed in January 2021. The TeamTNT activity group is believed to be behind Hildegard.

Techniques used27

Procedure examples27

TechniqueProcedure example
T1014
Rootkit

Hildegard has modified /etc/ld.so.preload to overwrite readdir() and readdir64().

T1027.002
Software Packing

Hildegard has packed ELF files into other binaries.

T1027.013
Encrypted/Encoded File

Hildegard has encrypted an ELF file.

T1036.004
Masquerade Task or Service

Hildegard has disguised itself as a known Linux process.

T1046
Network Service Discovery

Hildegard has used masscan to look for kubelets in the internal Kubernetes network.

T1059.004
Unix Shell

Hildegard has used shell scripts for execution.

T1068
Exploitation for Privilege Escalation

Hildegard has used the BOtB tool which exploits CVE-2019-5736.

T1070.003
Clear Command History

Hildegard has used history -c to clear script shell logs.

T1070.004
File Deletion

Hildegard has deleted scripts after execution.

T1071
Application Layer Protocol

Hildegard has used an IRC channel for C2 communications.

T1082
System Information Discovery

Hildegard has collected the host's OS, CPU, and memory information.

T1102
Web Service

Hildegard has downloaded scripts from GitHub.

T1105
Ingress Tool Transfer

Hildegard has downloaded additional scripts that build and run Monero cryptocurrency miners.

T1133
External Remote Services

Hildegard was executed through an unsecure kubelet that allowed anonymous access to the victim environment.

T1136.001
Local Account

Hildegard has created a user named “monerodaemon”.

View all 27 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Unit 42 Hildegard Malware Open source
    Chen, J. et al. (2021, February 3). Hildegard: New TeamTNT Cryptojacking Malware Targeting Kubernetes. Retrieved April 5, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.