Hildegard is cryptojacking malware developed by TeamTNT that targets Linux-based Kubernetes environments, including cloud-hosted container workloads. It gains access through exposed, insecure kubelets that permit anonymous access, allowing attackers to execute malware within containers. Its mining activity uses XMRig to generate Monero by consuming compromised systems’ computing resources.
Hildegard searches for SSH private keys, Docker credentials, and Kubernetes service tokens, and uses masscan to discover additional kubelets within internal Kubernetes networks. It creates local user accounts to support persistence and uses the BOtB container-breakout tool, which exploits CVE-2019-5736 in runC, for privilege escalation and escape from container isolation. Its defense-evasion behaviors include decrypting AES-encrypted ELF payloads, deleting scripts after execution, and modifying DNS resolver settings to evade DNS monitoring.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Hildegard has used the BOtB tool which exploits CVE-2019-5736.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
45 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cryptojacking malware targeting Kubernetes, referenced in the additional resources section.
Malware used in TeamTNT’s Kubernetes-focused campaign to compromise exposed kubelet environments, deploy mining activity, and maintain access using reverse shell/Tsunami/tmate-related tooling.
Executed through an insecure kubelet permitting anonymous access to a victim environment; further capabilities are not described.
Custom cryptojacking malware developed by TeamTNT.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.