Hildegard

MITRE ATT&CK: S0601 View on attack.mitre.org

Aliases: Hildegard

First seen
2021-01-01 00:00:00
Malware type
cryptominer
Family
Malware family
Operating systems
linux, containers, iaas
Profile updated
2026-07-07 12:58:58

Targeted industries: technology-and-telecommunications

Context

Hildegard is malware that targets misconfigured kubelets for initial access and runs cryptocurrency miner operations. The malware was first observed in January 2021. The TeamTNT activity group is believed to be behind Hildegard.

Detection coverage

  • 437 Sigma rules

Malware & tools used

  • Application Layer Protocol (attack-pattern)
  • Private Keys (attack-pattern)
  • File Deletion (attack-pattern)
  • Container Administration Command (attack-pattern)
  • Container and Resource Discovery (attack-pattern)
  • Dynamic Linker Hijacking (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • External Remote Services (attack-pattern)
  • Credentials In Files (attack-pattern)
  • Software Packing (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Web Service (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Rootkit (attack-pattern)
  • Clear Command History (attack-pattern)
  • Remote Access Tools (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Compute Hijacking (attack-pattern)
  • Local Account (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Cloud Instance Metadata API (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Systemd Service (attack-pattern)
  • Escape to Host (attack-pattern)

Used by threat actors

Reports & references

  • Palo Alto Unit 42 — Hildegard Malware Teamtnt (report)
  • MITRE ATT&CK — S0601 (report)

External references