Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Trident Announces Termination of Deposit Agreement, Concurrent Changes to Share Capital and Direct Listing of Ordinary Shares

June 16, 2026

Onchain Data Locks In Satoshi’s 1.1M BTC Hoard — 3 Theories on Why It Never Moves

June 16, 2026

Iren acquires Spanish AI data center developer Nostrum Group

June 16, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»TeamTNT Targeted Cloud Instances and Containerized Environments For Two Years
TeamTNT Targeted Cloud Instances and Containerized Environments For Two Years
Security

TeamTNT Targeted Cloud Instances and Containerized Environments For Two Years

October 24, 2023No Comments2 Mins Read

The threat actor known as TeamTNT has been targeting cloud instances and containerized environments on systems around the world for at least two years.

The findings come from CloudSEK security researchers, who posted an advisory on Thursday detailing a timeline of TeamTNT attacks from February 2020 until July 2021.

According to the report, the group’s Github profile contains 25 public repositories, most of which are forks of popular red teaming tools and other repositories possibly utilized by them.

Additionally, the domain spotted by CloudSEK and allegedly associated with TeamTNT was registered on February 10, 2020, the same time period when the team began to target Redis servers actively. 

In these initial campaigns, CloudSEK said the aim of TeamTNT was cryptojacking, as the group deployed a number of tools typically used for these attacks, including pnscan, Tsunami and xmrigCC, among others.

TeamTNT then reportedly started attacking Docker instances in May 2020, mostly using the same cryptojacking-focussed tools but introducing the use of TCP port scanner masscan in conjunction with malicious Alpine images.

Throughout August 2020, the cybercriminal group continued their attacks on Docker, but they started using the Ubuntu images directly instead of Alpine. They also deployed the Linux Kernel Module (LKM) rootkit known as Diamorphine to hide their activities on infected machines.

Months later, they started exploiting Weavescope for troubleshooting and leveraging it as a backdoor, and in January 2021, a report by Lacework Labs suggested TeamTNT was using three new hacking tools targeting Kubernetes: Peirates, Botb, and libprocesshider.

In the second half of 2021, the group’s target list reportedly remained the same, but they expanded their credential-stealing capabilities to additional services and applications, including AWS, Filezilla and GitHub, among others. In July, TeamTNT launched a campaign named ‘Chimaera,’ suggesting the group continued their attacks on Docker, Kubernetes, and Weavescope services.

See also  US Service Members Targeted Via Commercial Location Data, Pentagon Tells Senators

At the time of writing, the domain associated with TeamTNT is now offline, but the CloudSEK advisory suggested some screenshots of the domain are still available on Wayback Machine.

The security researchers suggested the group most likely originated from Germany because most of the tweets and bash scripts (including comments) are in German, and the account’s location is set to ‘Deutschland’.

Source link

cloud Containerized Environments Instances Targeted TeamTNT years

Related Posts

India’s NHRC Raises Alarm Over Digital Arrest Scams

June 16, 2026

Rokarolla Trojan Combines Banking Fraud With Device Surveillance

June 16, 2026

Pyra to Cease Operations Following Drift Hack, Launches Fund Withdrawal Portal

June 16, 2026

Oklahoma Raises Alarm Over Fake Crypto Returns

June 16, 2026
Top Posts

Galaxy Digital's testnet suffers hack but no client funds or information were compromised

April 2, 2026

LDO Price Prediction: Oversold Rally to $0.32 Before Bear Trend Resumes

June 10, 2026

Bitcoin Financial Services Firm Unchained Looks to Attract Wealthy Clients With New Advisory Service

October 18, 2023

Type above and press Enter to search. Press Esc to cancel.