🇩🇪

TeamTNT

APT Group 39 zero-day CVEs

Also Known As 1 names

Adept Libra

Target Countries 3

Countries highlighted in red

Belgium India United States

Details

Origin 🇩🇪 DE
Last Updated 01 Jun 2022

MITRE ATT&CK 164

T1003 T1005 T1007 T1008 T1011 T1012 T1014 - Rootkit T1016 - System Network Configuration Discovery T1018 - Remote System Discovery T1021 T1021.004 - SSH T1026 T1027 - Obfuscated Files or Information T1027.002 T1027.013 T1030 T1033 - System Owner/User Discovery T1036 - Masquerading T1036.005 T1040 T1041 T1046 - Network Service Scanning T1047 T1048 T1049 - System Network Connections Discovery T1053 T1053.003 - Cron T1055 T1056 - Input Capture T1057 T1059 - Command and Scripting Interpreter T1059.001 T1059.003 T1059.004 - Unix Shell T1059.009 T1059.013 T1060 T1065 T1068 T1070 - Indicator Removal on Host T1070.002 T1070.003 T1070.004 - File Deletion T1071 T1071.001 - Web Protocols T1071.004 - DNS T1074 T1074.001 T1078 - Valid Accounts T1080 - Taint Shared Content T1081 T1082 - System Information Discovery T1083 - File and Directory Discovery T1085 T1087 T1090 - Proxy T1095 - Non-Application Layer Protocol T1098 T1098.004 T1102 - Web Service T1104 T1105 - Ingress Tool Transfer T1106 T1110 - Brute Force T1111 T1112 T1113 - Screen Capture T1114 T1114.001 T1115 T1119 T1120 T1123 T1124 T1127 T1130 T1132 T1133 T1134 - Access Token Manipulation T1136 T1136.001 T1137 T1140 - Deobfuscate/Decode Files or Information T1170 T1176 T1190 - Exploit Public-Facing Application T1195 T1199 - Trusted Relationship T1203 T1204 - User Execution T1204.002 T1204.003 T1217 T1218 - Signed Binary Proxy Execution T1219 T1222 T1222.002 T1437 T1485 T1486 T1489 T1490 - Inhibit System Recovery T1496 - Resource Hijacking T1496.001 T1497 - Virtualization/Sandbox Evasion T1497.003 T1498 - Network Denial of Service T1499 T1503 T1505 T1518 - Software Discovery T1518.001 T1525 - Implant Internal Image T1526 T1529 T1530 - Data from Cloud Storage Object T1531 T1539 T1543 T1543.002 - Systemd Service T1543.003 T1546 T1547 T1547.001 T1550 T1552 - Unsecured Credentials T1552.001 - Credentials In Files T1552.004 T1552.005 T1553 - Subvert Trust Controls T1555 T1560 T1561 T1562 - Impair Defenses T1562.001 - Disable or Modify Tools T1562.004 T1564 - Hide Artifacts T1565 T1566 - Phishing T1569 T1569.001 - Launchctl T1569.002 - Service Execution T1569.003 T1571 T1573 T1574 - Hijack Execution Flow T1583 - Acquire Infrastructure T1583.001 T1584 T1587 T1587.001 T1595 T1595.001 T1595.002 T1608 T1608.001 T1609 T1610 - Deploy Container T1611 T1613 - Container and Resource Discovery T1680 T1685 T1685.006 T1686