Black-T
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Unit 42 researchers discovered a new variant of cryptojacking malware named Black-T, authored by TeamTNT... Black-T follows the traditional TeamTNT tactics... targeting exposed Docker daemon APIs and performing scanning and cryptojacking operations...
Techniques & procedures
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
1 technique"targeting exposed Docker daemon APIs ... on compromised cloud systems"; "downloaded ... to the compromised cloud system that maintained an exposed Docker daemon API"
Credential Access
2 techniques"memory password scraping operations via mimipy and mimipenguins"; "Upon uncovering any passwords residing in memory... written to ... output.txt"
"group known to target AWS credential files"; "still targeting AWS credential and configuration files located on compromised AWS cloud systems"; files collected include "/root/.aws/"
Discovery
1 technique"capability to use three different network scanning tools to identify additional exposed Docker daemon APIs... Both masscan and pnscan... addition of zgrab"; "addition of a new scanning port, TCP 5555"; "performs scanning operations on a random CIDR 8 network range"
Command and Control
1 technique"downloaded from the TeamTNT domain... to the compromised cloud system"; "downloads two files, which execute directly into bash"; multiple hxxps://teamtnt[.]red/... payload URLs
Exfiltration
1 technique"tar files... then sent to the URL hxxps://teamtnt[.]red/only_for_stats/dup.php"; "output.txt ... uploaded to hxxps://teamtnt[.]red/only_for_stats/dup.php"
Impact
2 techniques"mine for Monero (XMR)"; "downloads the known XMR miner software sbin_u"; "configures the XMR mining software to use... XMR wallet address"
"naming 8.8.4.4 and 8.8.8.8 as new DNS servers... flushing all established IP table rules using the command iptables -F"; "setting Path Variables"
Other
1 techniqueIOCs tracked for this family
51 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
Recent activity
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.