Team TNT
Overview
Tactics & Techniques
Team TNT has use Tsunami Malware as a part of their tactics and techniques. It is a botnet that specifically targets Linux systems. It has the ability to connect wit Command and Control (C2) server vis Internet Relay Chat (IRC) protocol. The server controls the botnet and issues commands to the infected systems. It operates (C2) via IRC channels, functioning like chat rooms on the IRC network. Every infected system join a specific channel on IRC server, and waits for commands.
The instruction command might include downloading additional malware or performing other malicious activities, transforming the infected system into a backdoor for various malicious purposes.
Hence, the features of Tsunami includes successfully hiding its processes and files to avoid detection, automatically reconnect to the C2 server if the connection is lost, and maintaining control over the compromised system.
Comments
Post a Comment