TeamTNT
Essential information
- Confidence
- 100/100
- Published
- 16/12/2025 19:39
- Modified
- 27/03/2026 01:13
- Updated at
- 27/03/2026 01:13
- Revoked
- No
- Author / Source
- The MITRE Corporation
- Resource level
- —
- Primary motivation
- —
- Related entities
- 2 reports, 85 attack patterns (mitre), 6 malware, 1 countries, 105 indicators, 3 tool
Description
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (2)
-
21 MITREs 2 Malwares 35 Observables 1 APTPublished 18/12/2024 06:34 · Modified 18/12/2024 12:09
-
14 MITREs 2 Malwares 11 Observables 1 APTPublished 29/10/2024 13:51 · Modified 29/10/2024 13:57
Attack patterns (MITRE) (85)
-
T1595.002 usesVulnerability Scanning
-
T1587.001 usesMalware
-
T1071.001 usesWeb Protocols
-
T1102 usesWeb Service
-
T1078 usesValid Accounts
-
T1059.003 usesWindows Command Shell
-
T1613 usesContainer and Resource Discovery
-
T1190 usesExploit Public-Facing Application
-
T1007 usesSystem Service Discovery
-
T1027.002 usesSoftware Packing
-
T1562 usesImpair Defenses
-
T1526 usesCloud Service Discovery
-
T1036.005 usesMatch Legitimate Resource Name or Location
-
T1543.003 usesWindows Service
-
T1569 usesSystem Services
-
Compute Hijacking uses
-
T1204.003 usesMalicious Image
-
T1609 usesContainer Administration Command
-
T1046 usesNetwork Service Discovery
-
T1134 usesAccess Token Manipulation
-
Systemctl uses
-
T1014 usesRootkit
-
T1027 usesObfuscated Files or Information
-
T1105 usesIngress Tool Transfer
-
T1059.001 usesPowerShell
-
Cloud API uses
-
T1083 usesFile and Directory Discovery
-
T1199 usesTrusted Relationship
-
T1059 usesCommand and Scripting Interpreter
-
T1071 usesApplication Layer Protocol
-
T1574 usesHijack Execution Flow
-
T1059.004 usesUnix Shell
-
T1021.004 usesSSH
-
T1496 usesResource Hijacking
-
T1569.001 usesLaunchctl
-
T1070.004 usesFile Deletion
-
T1018 usesRemote System Discovery
-
T1222.002 usesLinux and Mac File and Directory Permissions Modification
-
T1608.001 usesUpload Malware
-
T1049 usesSystem Network Connections Discovery
-
T1070.002 usesClear Linux or Mac System Logs
-
T1074.001 usesLocal Data Staging
-
T1070.003 usesClear Command History
-
T1098.004 usesSSH Authorized Keys
-
T1497 usesVirtualization/Sandbox Evasion
-
T1547 usesBoot or Logon Autostart Execution
-
T1219 usesRemote Access Tools
-
Container CLI/API uses
-
T1057 usesProcess Discovery
-
T1562.004 usesDisable or Modify System Firewall
-
T1564 usesHide Artifacts
-
T1611 usesEscape to Host
-
T1578 usesModify Cloud Compute Infrastructure
-
T1552.005 usesCloud Instance Metadata API
-
T1552.001 usesCredentials In Files
-
T1053.003 usesCron
-
T1518 usesSoftware Discovery
-
T1547.001 usesRegistry Run Keys / Startup Folder
-
T1562.001 usesDisable or Modify Tools
-
T1082 usesSystem Information Discovery
-
T1552.004 usesPrivate Keys
-
T1595.001 usesScanning IP Blocks
-
T1120 usesPeripheral Device Discovery
-
T1090 usesProxy
-
T1140 usesDeobfuscate/Decode Files or Information
-
T1525 usesImplant Internal Image
-
T1518.001 usesSecurity Software Discovery
-
T1610 usesDeploy Container
-
T1071.004 usesDNS
-
T1583.001 usesDomains
-
T1136.001 usesLocal Account
-
T1041 usesExfiltration Over C2 Channel
-
T1036 usesMasquerading
-
T1569.002 usesService Execution
-
T1543.002 usesSystemd Service
-
T1133 usesExternal Remote Services
-
T1048 usesExfiltration Over Alternative Protocol
-
T1033 usesSystem Owner/User Discovery
-
T1016 usesSystem Network Configuration Discovery
-
T1552 usesUnsecured Credentials
Malware (6)
- Hildegard
-
Tsunami usesFamilyPublished 14/04/2026 08:54 · Modified 14/04/2026 08:54
-
XMRig usesFamilyPublished 28/05/2026 10:56 · Modified 28/05/2026 10:56
-
Platypus usesFamilyPublished 18/12/2024 06:34 · Modified 18/12/2024 06:34
-
Sliver usesFamilyPublished 12/06/2026 21:29 · Modified 12/06/2026 21:29
- Black-T
Countries (1)
- Germany targets
Indicators (105)
-
d2fff992e40ce18ff81b9a92fa1cb93a56fb5a82c1cc428204552d8dfa1bc04findicates -
64d8f887e33781bb814eaefa98dd64368da9a8d38bd9da4a76f04a23b6eb9de5indicates -
5bb45f372fb4df6a9c6a5460fa1845f5e96af53aa41939eb251cbe989a5cac6cindicates -
0cdad862a1a695fe9cbf35592f92111e31ac848881fcd1deaa3c6ecd7c241ad7indicates -
e137bf61096f68478a0daa63fca1b2cc45a99f2dfdcd08d7ff7c449f38cf5ce9indicates -
https://9-9-8.comindicates -
f26f805c3a1c01ab4717cc3b4c91581249482b00bd29712ab0c36ba7ce74147cindicates -
900b17ae0081052fb63a7d74232048cfbc2716cdedbe0ab14cf64b7d387d4329indicates -
61e94f41187a3ce31fd8ac0ae3798aaa0e8984e8ff76debe623e41fecf8d7a12indicates -
e9a58f006e5335d806da5fc772fb2b5dedcd977d6484f462169f7a64a636fb44indicates -
5b9acfd34a30a3f26db492ed4404d518d583c0088a38a7622b683407c34b9108indicates -
d4508f8e722f2f3ddd49023e7689d8c65389f65c871ef12e3a6635bbaeb7eb6eindicates -
b1f38b8648351bb7c743eed838658ea38975db40358c2af62d4e36905555a332indicates -
https://b.9-9-8.com/brysj/w.shindicates -
http://b.9-9-8.com/brysj/w.shindicates -
http://45.9.148.35/chimaera/bin/indicates -
49b185d1a03124fd5f664fe908fe833d932124344216535b822a044e9d115234indicates -
84078b10ad532834eb771231a068862182efb93ce1e4a8614dfca5ae3229ed94indicates -
d5063df016a6af531ed4e6dd222ff4dbbb5b3b0c9075ad642e94adde8e481cbeindicates -
bcd43d4046c64d15da4e87984306dd14dc80daa904a6477ad2b921c49c2f414dindicates -
http://b.9-9-8.com/brysj/ar.shindicates -
79c7a022d2c807dea005fb5c0433eb984eea053d07123754acd864bede03be00indicates -
4a6a31b867ce9033691a6638997b0e46d89462d677e9a1f7d757e9f2efbd4c79indicates -
3ae9e772a025d192a689358e263445a8d953e090b1bbe62f83567034938e75b5indicates -
d708b28231ef70edc707d3cfc1f9ed72aa06a6db15b7903a22b2cdba435e41f7indicates -
5ac76e1edfda445548c35364ba0c3dbb0bcb8a0236c303d2a4e2a94a7073a716indicates -
456041c34e7a992e76320121b7a6b5a47f12b1ed069e1de735543f5b2a1f1a68indicates -
18137be62c9267cf6b0b40432a91c5818c66bdaa42aad3728c598d3fc65fdcffindicates -
bbcdffd6fa3b1370dfc091bfd3bfca38be013f72f94af7ef29466d911c9604d8indicates -
43545f6cd370e6f200347bd9bbafdc3d94240775d816cd5e24dc8072d0f1c9b5indicates -
e842c810b6ecb9c7634f1cfbf81b6245094528ac5584179eb8e6932eaa34f421indicates -
mine.c3pool.comindicates -
e6e1656ac258318e8226db00dbacdf6914f2dac2d174b1470903b096b7fbecffindicates -
https://b.9-9-8.com/brysj/m/enbash.tarindicates -
https://b.9-9-8.com/brysj/d/ar.shindicates -
3aae4a2bf41aedaa3b12a2a97398fa89a9818b4bec433c20b4e724505277af83indicates -
donaldtrump.ccindicates -
12466d33f1d0e9114b4c20e14d51ca3e7e374b866c57adb6ba5dfef3ee34ee5bindicates -
e8cd937239d6bf43cb34c7947321a197b0d1067f05c3b21508bffa35a953a3c3indicates -
e673ef9910a9d6319be598be72430f1b04c299b48e5cd95ce7ccafac273072f3indicates -
bb89a6bbddc5dda36542a5fef230b8fa9d98fbdb0ec4fa1794b8c28a0b5a3af4indicates -
de3747a880c4b69ecaa92810f4aac20fe5f6d414d9ced29f1f7ebb82cd0f3945indicates -
ee7799a42c2f487df7405d0aac06496c9a5bb58daecfb135f6f58e3b3aeedf69indicates -
9504b74906cf2c4aba515de463f20c02107a00575658e4637ac838278440d1aeindicates -
881530fb9634cbf5cf12080f5d13e69cb9497c7ea223a4ac29e0d3c81de3053aindicates -
57689b87b6830411046d7bda19936707a0797bec9dffe03874d1a364c4f29c35indicates -
m.9-9-8.comindicates -
ec92f9a98e2c5449693792aa7fd77d0c7a5a98af13b0595ad3c46da739c44c80indicates -
d4084c84b21a24ec7a75b1700c65835edea55ac146e86f874941f9ea4bc30ecdindicates -
https://www.cadosecurity.com/blog/spinning-yarn-a-new-linux-malware-campaign-targets-docker-apache-hadoop-redis-and-confluence.indicates -
484d09b34cb7fb075647402b52f174b2645c6b2c7e8b271e648421893aacdfb4indicates -
http://45.9.148.35/chimaera/up/indicates -
3d2481edc5fe122bae2fe316d803e131837606e38a7a3158f7cddc7b436dc6c2indicates -
7e84f9aab329754fe4681d4d6e4c64098731fd55b5998d7cfacb08ba4dbdfd5cindicates -
https://b.9-9-8.com/brysj/m/enbio.tarindicates -
5f1c9e8dc98ff3e7cf32096225cbae96dacead6af82986d69bbc0032d0e8da84indicates -
5265a344fd3d3c91d1e9169678e9dadf6296331ccf91132b99c728761bffb011indicates -
c2491f9b1f6eb9b1b31e84b0dd5505c5959947c47230af97dce18a49aab90e6bindicates -
http://mine.c3pool.com:17777indicates -
37ba40494303ff2c671d6806977f655bdc6ae45ad09357214b164fd5328efb31indicates -
2f4ffa0e687b4e18e45770812a14ad4fc1ae3f735b4f8280f0dd241e045838feindicates -
fece70a9f33c2ed77a5833dba5b7188d5ec00a30fb00e43983e6939cac87fb99indicates -
44cbddf5092818092439734cd478a0fd80f93949e4fec32553b78064029266afindicates -
4e4e01830dc64466683735d32778d17cfbffc7be75d647322240ecf9e2f9d700indicates -
5ddd226d400cc0b49d0175ba06a7e55cb2f5e9586111464bcf7b3bd709417904indicates -
0d7912e62bc663c9ba6bff21ae809e458b227e3ceec0abac105d20d5dc533a22indicates -
https://b.9-9-8.com/brysj/indicates -
0c7579294124ddc32775d7cf6b28af21b908123e9ea6ec2d6af01a948caf8b87indicates -
http://45.9.148.35/chimaera/sh/indicates -
dc8e4e45a46a65e70e3d67315ca76127b20ef4dcda2fd012a826b73ee26ab941indicates -
1e565e0672c4cd60b7db32c0ecc1abace6dfd8b6c2e0623c949d31536940fd62indicates -
642551b7f4e088797cd37b19280261668c8b381dcf667ea7d0dafed1ec94e460indicates -
2287e71c5707ebb2885cd6afd0bff401e4465ca59c8c2498439859e6c8ec5175indicates -
15f8cf9c0ed9891f20be37130c1d0e30946e4e14e00a1b2824da22c6c94b8fe3indicates -
4e059d74e599757226f93ea8ddcfb794d4bcda605f0e553fbbef47b8b7c82d2bindicates -
3b14c84525f2e56fe3ae7dec09163a4a9c03f11e6a8d65b021c792ad13ed2701indicates -
8373c0e8abdd962f46d3808fb10589e4961e38cd96d68a4464d1811788a4f2b7indicates -
134e9ab62a8efe80a27e2869bd6e98d0afe635e0e0750eb117ff833dc9447c28indicates -
d15af7984ed9b33093d7d5725c84ab24edf7c4ff02af3ac0a6c3aa9d5f7e12f4indicates -
0af1b8cd042b6e2972c8ef43d98c0a0642047ec89493d315909629bcf185dffdindicates -
https://m.9-9-8.comindicates -
b.9-9-8.comindicates -
a698562d56715c138750163c84727a1f2edb9d92f231994abf7ae82ef62006bfindicates -
651a3034429358a0ccb2d58ecbe2b7f3e4ee1bf4bee3e7a86f7ca873f6049ec2indicates -
595497c407795e0dbb562a4616fd877ce1eb2e86424672bac8003662e1fa07ebindicates -
55a53f325a46f0da8a15ce001595b9d27eeb03262a62c40f169a3c855c5e8319indicates -
f9b5bd4372daf78346e4bb34677633a7795876a3c89c5965eb76f137a0fba448indicates -
825c60dd1bb32cd6b7e6686f425c461532093b1e9f6ca662c1ea9b07ec7e470bindicates -
6175648ebbe658e3d5984d5c45d5221bf8f8875599d9ce2d62d279b7bba5eeeaindicates -
bf9b11b764f63c32fd333cc3916c97490fb06f4dbcff8ae87dfee098eca1e854indicates -
7270416ff49d679f123f560f135b25afe1754a370b0a4bf99368f1ebbc86cbb1indicates -
0a8499cebddd96af4634e85be50e4f64c9d2c7c616677de171df99691239526bindicates -
d27eeb48b1a74efd8710ef4ce62ee8469dd2352b0079c5b1c82e8da43fe932a2indicates -
acea877b5e4eb9a4f89c0607872bd718e818775dd70044ba6bcede26b481d079indicates -
f194d5901d64811c72a2cf3a035b7c36ea36d444ea6291f64138d1e88929349dindicates -
24c75a2f86d3c0f13f77b453d476787607a87c1033dca501351846524a4e8ff6indicates -
afddbaec28b040bcbaa13decdc03c1b994d57de244befbdf2de9fe975cae50c4indicates -
b6ddd29b0f74c8cfbe429320e7f83427f8db67e829164b67b73ebbdcd75d162dindicates -
584c6efed8bbce5f2c52a52099aafb723268df799f4d464bf5582a9ee83165c1indicates -
https://tip.neiki.dev/file/64d8f887e33781bb814eaefa98dd64368da9a8d38bd9da4a76f04a23b6eb9de5/content.indicates -
http://b.9-9-8.com/brysjindicates -
http://45.9.148.35/chimaera/init/indicates -
b2e26c7ce901296822085164ede73557a10badfdf99d1aa30f338446d0beb2d7indicates -
11b45924f96844764c7ae56ce0b6ac3c43d3a732bc7101d7ce85ea52d0455afdindicates -
229d6e173f22a647c8db9c8e7d0b21c8f86dd4e270abb96548aa40d84457c99aindicates
Tool (3)
-
LaZagne usesThe MITRE Corporation Confidence 100
[LaZagne](https://attack.mitre.org/software/S0349) is a post-exploitation, open-source tool used to recover stored passwords on a system. It has modules for Windows, Linux, and OSX, but is mainly focused on Windows …
Published 30/01/2019 17:44 · Modified 27/03/2026 01:07 -
MimiPenguin usesThe MITRE Corporation Confidence 100
[MimiPenguin](https://attack.mitre.org/software/S0179) is a credential dumper, similar to [Mimikatz](https://attack.mitre.org/software/S0002), designed specifically for Linux platforms. (Citation: MimiPenguin GitHub May 2017)
Published 16/01/2018 17:13 · Modified 27/03/2026 01:07 -
Peirates usesThe MITRE Corporation Confidence 100
[Peirates](https://attack.mitre.org/software/S0683) is a post-exploitation Kubernetes exploitation framework with a focus on gathering service account tokens for lateral movement and privilege escalation. The tool is written in GoLang and …
Published 08/02/2022 17:11 · Modified 27/03/2026 01:07