Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S0601
MITRE ATT&CK Malware

Hildegard (S0601)

ShareXLinkedInRedditHN

[Hildegard](https://attack.mitre.org/software/S0601) is malware that targets misconfigured kubelets for initial access and runs cryptocurrency miner operations. The malware was first observed in January 2021. The TeamTNT activity group is believed to be behind [Hildegard](https://attack.mitre.org/software/S0601). (Citation: Unit 42 Hildegard Malware)

Platforms: Linux, Containers, IaaS

▪Techniques implemented (27)

T1071Application Layer ProtocolT1552.004Private KeysT1070.004File DeletionT1609Container Administration CommandT1613Container and Resource DiscoveryT1574.006Dynamic Linker HijackingT1046Network Service DiscoveryT1133External Remote ServicesT1552.001Credentials In FilesT1027.002Software PackingT1036.004Masquerade Task or ServiceT1082System Information DiscoveryT1102Web ServiceT1685Disable or Modify ToolsT1014RootkitT1070.003Clear Command HistoryT1219Remote Access ToolsT1140Deobfuscate/Decode Files or InformationT1496.001Compute HijackingT1136.001Local AccountT1105Ingress Tool TransferT1552.005Cloud Instance Metadata APIT1027.013Encrypted/Encoded FileT1543.002Systemd ServiceT1611Escape to HostT1068Exploitation for Privilege EscalationT1059.004Unix Shell

▪Used by groups (1)

G0139TeamTNT
S0601on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.