Hildegard
MITRE ATT&CK: S0601 View on attack.mitre.org
Aliases: Hildegard
- First seen
- 2021-01-01 00:00:00
- Malware type
- cryptominer
- Family
- Malware family
- Operating systems
- linux, containers, iaas
- Profile updated
- 2026-07-07 12:58:58
Targeted industries: technology-and-telecommunications
Context
Hildegard is malware that targets misconfigured kubelets for initial access and runs cryptocurrency miner operations. The malware was first observed in January 2021. The TeamTNT activity group is believed to be behind Hildegard.
Detection coverage
- 437 Sigma rules
Malware & tools used
- Application Layer Protocol (attack-pattern)
- Private Keys (attack-pattern)
- File Deletion (attack-pattern)
- Container Administration Command (attack-pattern)
- Container and Resource Discovery (attack-pattern)
- Dynamic Linker Hijacking (attack-pattern)
- Network Service Discovery (attack-pattern)
- External Remote Services (attack-pattern)
- Credentials In Files (attack-pattern)
- Software Packing (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- System Information Discovery (attack-pattern)
- Web Service (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Rootkit (attack-pattern)
- Clear Command History (attack-pattern)
- Remote Access Tools (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Compute Hijacking (attack-pattern)
- Local Account (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Cloud Instance Metadata API (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Systemd Service (attack-pattern)
- Escape to Host (attack-pattern)
Used by threat actors
- TeamTNT (threat-actor)
Reports & references
- Palo Alto Unit 42 — Hildegard Malware Teamtnt (report)
- MITRE ATT&CK — S0601 (report)