G0139 · 54 ATT&CK techniques · 3 correlated reports

TeamTNT

Aliases: None listed

TeamTNT is a threat group that has primarily targeted cloud and containerized environments. The group as been active since at least October 2019 and has mainly focused its efforts on leveraging cloud and container resources to deploy cryptocurrency miners in victim environments.

Open interactive actor investigation

ATT&CK techniques

T1133
External Remote Services
T1219
Remote Access Software
T1569
System Services
T1036.005
Match Legitimate Name or Location
T1222.002
Linux and Mac File and Directory Permissions Modification
T1070.004
File Deletion
T1609
Container Administration Command
T1059.004
Unix Shell
T1547.001
Registry Run Keys / Startup Folder
T1543.002
Systemd Service
T1136.001
Local Account
T1007
System Service Discovery
T1049
System Network Connections Discovery
T1562.004
Disable or Modify System Firewall
T1543.003
Windows Service
T1608.001
Upload Malware
T1059.003
Windows Command Shell
T1610
Deploy Container
T1613
Container and Resource Discovery
T1048
Exfiltration Over Alternative Protocol
T1057
Process Discovery
T1059.001
PowerShell
T1552.005
Cloud Instance Metadata API
T1070.003
Clear Command History
T1074.001
Local Data Staging
T1595.002
Vulnerability Scanning
T1027.002
Software Packing
T1204.003
Malicious Image
T1014
Rootkit
T1552.004
Private Keys
T1562.001
Disable or Modify Tools
T1611
Escape to Host
T1070.002
Clear Linux or Mac System Logs
T1595.001
Scanning IP Blocks
T1105
Ingress Tool Transfer
T1518.001
Security Software Discovery
T1496.001
Compute Hijacking
T1083
File and Directory Discovery
T1021.004
SSH
T1036
Masquerading
T1140
Deobfuscate/Decode Files or Information
T1082
System Information Discovery
T1027.013
Encrypted/Encoded File
T1016
System Network Configuration Discovery
T1046
Network Service Discovery
T1120
Peripheral Device Discovery
T1071
Application Layer Protocol
T1098.004
SSH Authorized Keys
T1583.001
Domains
T1059.009
Cloud API
T1071.001
Web Protocols
T1552.001
Credentials In Files
T1587.001
Malware
T1102
Web Service

Correlated CTI and IR reports

Continue the investigation