TeamTNT — APT Profile
TeamTNT is a threat group that has primarily targeted cloud and containerized environments. The group as been active since at least October 2019 and has mainly focused its efforts on leveraging cloud and container resources to deploy cryptocurrency miners in victim environments.Tools & malware
- Hildegard Cryptominer
- LaZagne Credential Harvesting
- MimiPenguin Credential Harvesting
- Peirates Remote Access Trojan
Vendor research
- TeamTNT Cryptomining Explosion Intezer
- Team TNT – The First Crypto-Mining Worm to Steal AWS Credentials Cado Security TeamTNT Worm
- Hildegard: New TeamTNT Cryptojacking Malware Targeting Kubernetes Unit 42
- Tracking the Activities of TeamTNT A Closer Look at a Cloud-Focused Malicious Actor Group Trend Micro
- Attackers Abusing Legitimate Cloud Monitoring Tools to Conduct Cyber Attacks Intezer
- TeamTNT with new campaign aka Chimaera ATT TeamTNT Chimaera
- Deep Analysis of TeamTNT Techniques Using Container Images to Attack Aqua
- Black-T: New Cryptojacking Variant from TeamTNT Palo Alto
- Taking TeamTNT's Docker Images Offline Lacework
- TeamTNT Cryptomining Explosion Intezer