Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors TeamTNT

Also known as: Adept Libra

Description

TeamTNT is a threat group that has primarily targeted cloud and containerized environments. The group as been active since at least October 2019 and has mainly focused its efforts on leveraging cloud and container resources to deploy cryptocurrency miners in victim environments.(Citation: Palo Alto Black-T October 2020)(Citation: Lacework TeamTNT May 2021)(Citation: Intezer TeamTNT September 2020)(Citation: Cado Security TeamTNT Worm August 2020)(Citation: Unit 42 Hildegard Malware)(Citation: Trend Micro TeamTNT)(Citation: ATT TeamTNT Chimaera September 2020)(Citation: Aqua TeamTNT August 2020)(Citation: Intezer TeamTNT Explosion September 2021)

AI Analysis

· 1 week ago

Executive Summary

TeamTNT is a sophisticated cyber threat actor primarily targeting cloud and containerized environments since at least October 2019. The group has focused on deploying cryptocurrency miners in victim environments, leveraging cloud resources to generate revenue through unauthorized compute operations.

Goals & Targeting

TeamTNT's primary objective appears to be generating revenue through unauthorized cryptocurrency mining operations. The group's targeting focus on sectors with abundant cloud resources, such as IT, financial services, and education, is likely driven by the need for computational power to maximize mining profitability. While specific country targets are not fully detailed in available intelligence, TeamTNT's global footprint suggests a broad geographic targeting approach.

Enhanced Description

TeamTNT is known for its focus on cloud infrastructure attacks, specifically targeting Kubernetes clusters and container environments. The group has demonstrated a high level of technical proficiency by using sophisticated techniques to gain initial access, escalate privileges, and deploy cryptocurrency-mining malware. TeamTNT's operations often involve the abuse of legitimate cloud APIs and misconfigured containers to execute malicious activities, which can lead to significant financial losses for victim organizations. Campaigns attributed to TeamTNT have been observed leveraging custom tools and scripts tailored for cloud environments, as well as repurposing existing malware for new attack vectors.

Key Capabilities

  • Advanced persistence techniques in cloud environments
  • Abuse of container orchestration systems (e.g., Kubernetes)
  • Leveraging legitimate cloud APIs for malicious purposes
  • Custom malware development and deployment
  • Credential harvesting and lateral movement within networks

MITRE ATT&CK Tactics

Initial Access
Execution
Defense Evasion
Credential Access
Discovery
Collection
Exfiltration

ATT&CK Techniques

T1613
T1014
T1133
T1027.002
T1595.002
T1610
T1059.001
T1608.001
T1496.001

Software / Tooling

Hildegard

Campaigns & Victims

TeamTNT has been observed conducting multiple campaigns targeting cloud environments, with activities detected across various industries. The group's operational tempo appears to be opportunistic, capitalizing on misconfigured or vulnerable cloud resources. Notable operations include the deployment of crypto-mining malware and the manipulation of container instances to create long-term persistence.

IOC Patterns

  • Abuse of Kubernetes API endpoints
  • Unusual container instance activity
  • Leverage of legitimate cloud services for malicious purposes
  • Excessive compute resource usage indicative of mining operations

Recommended Actions

  • Implement stringent controls over cloud API access and usage.
  • Regularly audit and remediate misconfigured cloud resources.
  • Monitor for unusual activity in container orchestration platforms.
  • Enable logging and monitoring for Kubernetes and container environments.

Suggested Tags

APT
Cloud Threat
Crypto-Mining
Container Exploitation

Confidence Assessment

High confidence in TeamTNT's existence and primary activities targeting cloud environments. Some details, such as specific motivation beyond financial gain and exact targeting criteria, remain unclear or inferred from observed behavior.

ATT&CK Techniques

Command & Control
5 techniques
Discovery
11 techniques
Execution
9 techniques
Persistence
6 techniques
Stealth
8 techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. ATT TeamTNT Chimaera September 2020 — AT&T Alien Labs. (2021, September 8). TeamTNT with new campaign aka Chimaera. Retrieved September 22, 2021.
  2. Cado Security TeamTNT Worm August 2020 — Cado Security. (2020, August 16). Team TNT – The First Crypto-Mining Worm to Steal AWS Credentials. Retrieved September 22, 2021.
  3. Unit 42 Hildegard Malware — Chen, J. et al. (2021, February 3). Hildegard: New TeamTNT Cryptojacking Malware Targeting Kubernetes. Retrieved April 5, 2021.
  4. Trend Micro TeamTNT — Fiser, D. Oliveira, A. (n.d.). Tracking the Activities of TeamTNT A Closer Look at a Cloud-Focused Malicious Actor Group. Retrieved September 22, 2021.
  5. Intezer TeamTNT September 2020 — Fishbein, N. (2020, September 8). Attackers Abusing Legitimate Cloud Monitoring Tools to Conduct Cyber Attacks. Retrieved September 22, 2021.
  6. Intezer TeamTNT Explosion September 2021 — Intezer. (2021, September 1). TeamTNT Cryptomining Explosion. Retrieved October 15, 2021.
  7. Aqua TeamTNT August 2020 — Kol, Roi. Morag, A. (2020, August 25). Deep Analysis of TeamTNT Techniques Using Container Images to Attack. Retrieved September 22, 2021.
  8. Palo Alto Black-T October 2020 — Quist, N. (2020, October 5). Black-T: New Cryptojacking Variant from TeamTNT. Retrieved September 22, 2021.
  9. Lacework TeamTNT May 2021 — Stroud, J. (2021, May 25). Taking TeamTNT's Docker Images Offline. Retrieved September 16, 2024.

Intel Summary

56

Techniques

1

Tools

0

Campaigns

5

IOCs

0

Observed Data

14

Tactics

Tags

Financial Targeting
APT
Cloud Threat
Crypto-Mining
Container Exploitation

Details

MITRE ID
G0139
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--35d1b3be-49d4-42f1-aaa6-ef159c880bca
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.