TeamTNT

Threat Actor updated a month ago (2024-11-29T13:56:09.318Z)
Download STIX
Preview STIX
TeamTNT is a prominent threat actor known for executing sophisticated attacks with malicious intent, primarily focusing on cryptojacking - the unauthorized use of victims' IT resources to mine cryptocurrency. The group's Hildegard malware has been identified as one of the most complex attacks targeting Kubernetes, demonstrating TeamTNT’s advanced skills in automating its attacks and meticulous planning from initial access to preventing recovery attempts. The group's Docker Gatling Gun Campaign illustrates their intent to cause significant damage to their victims. Despite beliefs that the group "evaporated" in 2022, new evidence suggests continued activity into 2023. The P2PInfect worm's unique infection vector, exploiting Redis through CVE-2022-0543, sets it apart from other cryptojacking-focused worms known to target Redis instances, such as those created by Adept Libra (aka TeamTNT), Thief Libra (aka WatchDog) threat actors, or ones delivering Money Libra (aka Kinsing) variants. This tactic, along with others used by the attackers, indicates a new campaign from TeamTNT, referred to as the Hildegard campaign, named after the tmate account username used by the malware. An overlap of TeamTNT tactics, techniques, and procedures (TTPs) with ongoing campaigns dating back to last year was revealed in Group-IB’s latest report. Despite challenges in attribution, similarities in shell script payloads hint at potential connections to previous cloud attacks by threat actors like TeamTNT, WatchDog, and the Kiss a Dog campaign. For instance, cloud security company Sysdig found that TeamTNT mined over $8,100 worth of cryptocurrency from hijacked cloud infrastructure, costing their victims more than $430,000. In 2023, SentinelOne and Aqua Security studied a TeamTNT cryptojacking campaign that targeted Google Cloud, Microsoft Azure, and Amazon Web Services (AWS), further underscoring the group's significant threat to cloud infrastructures.
Description last updated: 2024-10-29T20:03:58.337Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Thief Libra is a possible alias for TeamTNT. Thief Libra, also known as WatchDog, is a threat actor identified in the cybersecurity world for its malicious activities. The group's operations involve exploiting vulnerabilities to execute actions with harmful intent. A notable aspect of Thief Libra's modus operandi involves targeting Redis insta
2
Adept Libra is a possible alias for TeamTNT. Adept Libra, also known as TeamTNT, is a malicious threat actor that has been active in cybersecurity breaches since at least July 2021. The group is known for its innovative use of tools such as LaZagne to steal passwords from various operating systems, including Linux distributions in cloud-based
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Aws
Malware
Docker
Linux
Credentials
Worm
Cybercrime
Kubernetes
Azure
Redis
LaZagne
Nginx
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Malware
To see the evidence that has resulted in these malware associations, create a free account
Alias DescriptionAssociation TypeVotes
The P2pinfect Malware is associated with TeamTNT. P2Pinfect is a form of malware, malicious software designed to infiltrate and damage computer systems or devices without the user's knowledge. It can enter your system through suspicious downloads, emails, or websites and once inside, it has the ability to steal personal information, disrupt operatiUnspecified
2
Source Document References
Information about the TeamTNT Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
SANS ISC
6 days ago
BankInfoSecurity
2 months ago
Securityaffairs
2 months ago
InfoSecurity-magazine
3 months ago
Securityaffairs
3 months ago
InfoSecurity-magazine
10 months ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
2 years ago
CERT-EU
a year ago
InfoSecurity-magazine
a year ago
Trend Micro
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
Unit42
a year ago
CERT-EU
a year ago