Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

1,003.62 ETH recovered after 9 years – How did a whitehat security researcher do it?

June 2, 2026

SEC Chair Paul Atkins Pushes Reform to Make US a Global Crypto Hub

June 2, 2026

Mouse, X-Agent, and UXLINK Unite to Revolutionize Interactive Gaming and Social Growth

June 2, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Cryptojacking Gang TeamTNT Make a Comeback
Cryptojacking Gang TeamTNT Make a Comeback
Security and Privacy

Cryptojacking Gang TeamTNT Make a Comeback

September 19, 2024No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Security researchers have found new evidence of TeamTNT activity dating back to 2023, despite a commonly held belief that the group “evaporated” in 2022.

TeamTNT was a prolific threat actor known for cryptojacking attacks, which use victims’ IT resources to illegally mine for cryptocurrency.

The likely German-speaking actor first emerged in 2019 and became infamous for its “homebrewed malware using a comprehensive toolkit of shell scripts and malicious binaries,” according to Group-IB.

It would target vulnerable public instances of Redis, Kubernetes and Docker, stealing credentials and installing backdoors in its cryptojacking campaigns.

Read more on TeamTNT: Experts Warn of Impending TeamTNT Docker Attacks

Published yesterday, Group-IB’s latest report revealed an overlap of TeamTNT tactics, techniques and procedures (TTPs) with ongoing campaigns dating back to last year.

“Group-IB’s DFIR team identified clear evidence of a new campaign impacting VPS cloud infrastructures based on CentOS operating systems,” it said.

“The investigation revealed that the initial access was accomplished via a Secure Shell (SSH) brute force attack on the victim’s assets, during which the threat actor uploaded a malicious script. Our DFIR experts analyzed the script, which, once executed, checks if the host has already been compromised by searching for traces of logs generated by other miners.”

The malicious script also disables security features, deletes logs and modifies system files, according to the report. It kills any cryptocurrency mining processes it discovers, removes Docker containers and updates DNS settings to Google’s servers.

Group-IB added that the script installs the “Diamorphine” rootkit for stealth and root privileges, and uses custom tools to maintain persistence and control.

See also  SEC’s Gensler says BTC, ETH ‘not securities’ in a newly surfaced video

“It locks down the system by modifying file attributes, creating a backdoor user with root access, and erasing command history to hide its activities,” Group-IB said.

“The entire analysis underscores TeamTNT’s advanced skills in automating its attacks and considering every single aspect and detail, from the initial access to preventing recovery attempts, aiming to inflict significant damage on the victim.”

Source link

comeback Cryptojacking Gang TeamTNT
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Stake DAO Freezes Arbitrum vsdCRV Markets After Attacker Mints 5.4T Synthetic Tokens

May 29, 2026

Certik Unveils ‘Anti-Virus for AI Agents’ as Skill Marketplaces Face Hidden Threats

May 29, 2026

New Threat Actor Jinx-0164 Targets Crypto Developers on macOS

May 28, 2026

PureLogs Variant Steals Data via Purchase Order Lures

May 27, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Strategy Sits On $635M Paper Loss as Saylor Signals Fresh Bitcoin Buy

April 6, 2026

California governor approves strict crypto regulatory framework for 2025

October 15, 2023

South Korea’s Ruling Party Calls for Early Enforcement of Crypto Laws

May 24, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

1,003.62 ETH recovered after 9 years – How did a whitehat security researcher do it?

June 2, 2026

SEC Chair Paul Atkins Pushes Reform to Make US a Global Crypto Hub

June 2, 2026

Mouse, X-Agent, and UXLINK Unite to Revolutionize Interactive Gaming and Social Growth

June 2, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$69,692.00-4.35%
  • ethereumEthereum(ETH)$1,976.01-0.31%
  • tetherTether(USDT)$1.00-0.01%
  • binancecoinBNB(BNB)$680.65-1.22%
  • rippleXRP(XRP)$1.26-2.90%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$79.47-1.71%
  • tronTRON(TRX)$0.340491-3.14%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.042.12%
  • HyperliquidHyperliquid(HYPE)$71.32-0.96%