Frequently Asked Questions

Threats & Attack Campaigns

What is the TeamTNT Chimaera campaign and which systems does it target?

The TeamTNT Chimaera campaign is a cyberattack operation that uses open-source tools to steal usernames and passwords from infected machines. It targets multiple operating systems, including Windows, various Linux distributions (such as Alpine, commonly used in containers), AWS, Docker, and Kubernetes environments. The campaign has been active for about one month and has resulted in thousands of infections globally. Note: Detection rates for some malware samples remain low, making timely defense validation critical.

How does the Chimaera campaign steal credentials from infected machines?

The Chimaera campaign uses a new credentials stealer based on the open-source Lazagne tool. After modifying the bash history file to hide its activity, the malware installs dependencies and downloads a second-stage script that executes Lazagne. Lazagne retrieves passwords from various programs (browsers, sysadmin tools, WiFi, mail, databases) and uploads the results to the attacker's command-and-control server. The malware then deletes any downloaded files to cover its tracks. Note: Defenders should monitor for unusual use of credential dumping tools and unexpected network uploads.

What actions does the Chimaera malware perform on Windows systems?

On Windows, the Chimaera campaign downloads and installs tools required to unpack and execute the Xmrig cryptocurrency miner. It uses 7z for decompression and Nssm to add the miner as a service. Persistence is achieved by either installing as a service (if admin privileges are available) or adding a batch file to the startup folder. Note: Organizations should monitor for unauthorized mining activity and changes to system services or startup folders.

How does the Chimaera campaign compromise Kubernetes and AWS environments?

For Kubernetes, the malware installs a cryptocurrency miner, disables or uninstalls security products (such as Aegis Authenticator and Alibaba services), adds the attacker's SSH key for remote access, and modifies the host file. For AWS, the malware collects credentials (access keys, session tokens, root credentials, etc.) and uploads them to the attacker's server before cleaning up traces. Note: Defenders should audit SSH keys, monitor for unauthorized tool installations, and review cloud credential usage for anomalies.

Features & Capabilities

How can Cymulate help organizations defend against threats like TeamTNT's Chimaera campaign?

Cymulate enables organizations to simulate real-world attacks, including credential theft, crypto mining, and cloud-targeted threats, using its extensive threat library and customizable attack scenarios. The platform supports validation across Windows, Linux, cloud, and container environments, helping teams identify exploitable exposures and test their defenses against tactics used in campaigns like Chimaera. Note: Cymulate's effectiveness depends on regular updates and scenario customization; organizations with highly specialized environments may require additional tuning.

What types of threats can Cymulate validate?

Cymulate can validate advanced persistent threats (APTs), malware, phishing, ransomware, insider threats, network-based attacks, and web application attacks. The platform uses up-to-date threat intelligence and attack simulations to ensure coverage against the latest cyber threats. Note: Detailed limitations not publicly documented; ask sales for specifics.

What features does Cymulate offer for exposure management and threat simulation?

Cymulate provides a user-friendly dashboard, extensive threat simulation capabilities, updated malware Indicators of Compromise (IOCs), customizable reports, and user notifications. These features allow organizations to simulate emerging threats and manage exposure with actionable insights. Note: Some advanced reporting or integrations may require additional configuration.

Which operating systems and environments does Cymulate support for threat validation?

Cymulate supports validation across Windows, multiple Linux distributions (including Alpine for containers), AWS, Docker, and Kubernetes environments. This enables organizations to test their defenses against threats targeting a wide range of platforms. Note: For highly specialized or legacy environments, confirm compatibility with Cymulate support.

Technical Documentation & Resources

Where can I find technical documentation on Cymulate's exposure management and threat simulation capabilities?

Cymulate provides several technical resources:

Note: Some resources may require registration to access.

Support & Implementation

How easy is it to implement Cymulate and start running threat simulations?

Cymulate is designed for rapid deployment and ease of use. It operates in agentless mode, requiring no additional hardware or complex configuration. Customers can start running simulations almost immediately after deployment. User feedback highlights the intuitive interface and minimal training required. Note: For advanced integrations or custom scenarios, additional setup may be needed.

Security & Compliance

What security and compliance certifications does Cymulate hold?

Cymulate is certified for SOC2 Type II (covering security, availability, confidentiality, and privacy), ISO 27001:2013 (Information Security Management), ISO 27701 (Privacy Information Management), ISO 27017 (Cloud Security), and CSA STAR Level 1 (Cloud Controls Matrix compliance). These certifications demonstrate adherence to international security standards. Note: For the latest certification status, visit Security at Cymulate.

Pricing & Plans

How is Cymulate priced and what factors determine the cost?

Cymulate uses a subscription-based pricing model tailored to each organization's needs. The cost depends on the package selected, the number of assets covered, and the scenarios and vectors chosen. For a personalized quote, organizations are encouraged to schedule a demo with the Cymulate team. Note: Exact pricing is not publicly listed; contact sales for details.

Cymulate named a Customers' Choice in 2026 Gartner® Peer Insights™
Learn More
New: Cymulate Cowork for Agentic Cyber Defense Engineering
Learn More
New Bitsight Integration: Turn Threat Intelligence into Validated Security
Learn More
Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More

TeamTNT with new campaign aka Chimaera

September 9, 2021

Key takeaways: TeamTNT is using new, open source tools to steal usernames and passwords from infected machines. The group is targeting various operating systems including: Windows, different Linux distributions including Alpine (used for containers), AWS, Docker, and Kubernetes. The campaign has been active for approximately one month and is responsible for thousands of infections globally. Many malware samples still have zero antivirus (AV) detections and others have low detection rates. Analysis of components used in the "Chimaera" campaign New credentials stealer ("Lazagne" component) The malicious script starts its activity by modifying the bash history file. This hides any future commands executed from users using the "history" command on Linux. The script then installs its dependencies ('curl', 'bash', 'wget', 'pip', 'py3-pip', 'python3-pip'). Supported operating systems include different Linux distributions, such as Alpine Linux which is typically used in containers. Once the malware is finished with its "pre-setup," it downloads the second phase of the attack from its C&C, which includes another bash script ('run.sh') along with the Lazagne project. Lazagne is an open-source project available for different operating systems (Windows, Linux, and MacOS). Its developer describes the Lazagne tool as an application that can be used to retrieve multiple passwords stored on a local machine. Due to its capabilities, the tool has been added as a post exploitation module to the pupy project. It supports a wide range of programs, such as browsers (Chrome, Firefox, Opera, etc.), Sysadmin programs (such as CoreFTP, Putty, OpenSSH, etc. ), Wifi password, mail programs, databases, etc. The full list of supported programs can be found on the Lazagne page on Github. In this phase two of the attack, the second malicious script executes the Lazagne tool, saves its output into "laZagne.out.txt," and uploads it to the C&C using the curl command. At the end of the execution, the malware deletes any file that has been downloaded. Windows component - Set up a cryptocurrency miner For Windows operating systems, the attackers use a malicious script that downloads all the tools required for unpacking and executing the Xmrig miner. This includes the 7z tool for decompressing downloaded files and Nssm to add the miner as a service. The malware will setup the miner and then the miner will persist it in the system in two ways: 1) by adding itself as a service if the malware gains admin privileges or 2) by adding the batch file to the startup folder. Kubernetes root payload component This component is mainly responsible for installing a cryptocurrency miner on infected devices, allowing the attacker to connect remotely to the system using SSH. The malicious script uses the following steps to achieve its goal: Disabling or uninstalling security products on infected machines, such as Aegis Authenticator, quartz, and Alibaba services (AliSecGuard, AliYunDun, AliNet etc.). Adding the attacker's RSA-key to the list of known SSH host (allowing the attacker to connect the machine through SSH without the need of user/password in the system). Installing missing required tools for crypto mining. Modifying the host file. Setting up the XMRig crypto miner. Adding persistence for the XMR miner. Removing itself. TeamTNT AWS stealer Similar to the other TeamTNT components, the AWS stealer first installs missing dependencies. It then collects information from infected devices and stores the informaiton in a temporary file "/var/tmp/TeamTNT_AWS_STEALER.txt". This information includes: AWS default region AWS access key Id AWS secret access key AWS session token AWS user credentials AWS root credentials Shared credentials file Container credential relative URI When finished, the malware uploads all of the stored information to its C&C using curl command, and then it cleans up its traces.