Also known as: Adept Libra
TeamTNT is a threat group that has primarily targeted cloud and containerized environments. The group as been active since at least October 2019 and has mainly focused its efforts on leveraging cloud and container resources to deploy cryptocurrency miners in victim environments.(Citation: Palo Alto Black-T October 2020)(Citation: Lacework TeamTNT May 2021)(Citation: Intezer TeamTNT September 2020)(Citation: Cado Security TeamTNT Worm August 2020)(Citation: Unit 42 Hildegard Malware)(Citation: Trend Micro TeamTNT)(Citation: ATT TeamTNT Chimaera September 2020)(Citation: Aqua TeamTNT August 2020)(Citation: Intezer TeamTNT Explosion September 2021)
Executive Summary
TeamTNT is a sophisticated cyber threat actor primarily targeting cloud and containerized environments since at least October 2019. The group has focused on deploying cryptocurrency miners in victim environments, leveraging cloud resources to generate revenue through unauthorized compute operations.
Goals & Targeting
TeamTNT's primary objective appears to be generating revenue through unauthorized cryptocurrency mining operations. The group's targeting focus on sectors with abundant cloud resources, such as IT, financial services, and education, is likely driven by the need for computational power to maximize mining profitability. While specific country targets are not fully detailed in available intelligence, TeamTNT's global footprint suggests a broad geographic targeting approach.
Enhanced Description
TeamTNT is known for its focus on cloud infrastructure attacks, specifically targeting Kubernetes clusters and container environments. The group has demonstrated a high level of technical proficiency by using sophisticated techniques to gain initial access, escalate privileges, and deploy cryptocurrency-mining malware. TeamTNT's operations often involve the abuse of legitimate cloud APIs and misconfigured containers to execute malicious activities, which can lead to significant financial losses for victim organizations. Campaigns attributed to TeamTNT have been observed leveraging custom tools and scripts tailored for cloud environments, as well as repurposing existing malware for new attack vectors.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TeamTNT has been observed conducting multiple campaigns targeting cloud environments, with activities detected across various industries. The group's operational tempo appears to be opportunistic, capitalizing on misconfigured or vulnerable cloud resources. Notable operations include the deployment of crypto-mining malware and the manipulation of container instances to create long-term persistence.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in TeamTNT's existence and primary activities targeting cloud environments. Some details, such as specific motivation beyond financial gain and exact targeting criteria, remain unclear or inferred from observed behavior.
No campaigns linked yet.
No observed data linked yet.
56
Techniques
1
Tools
0
Campaigns
5
IOCs
0
Observed Data
14
Tactics