Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Olenox Announces Merge With CS Digital to Develop Low Cost, Off-Grid Bitcoin Mining Opportunities

April 26, 2026

Trump defends crypto legislation at private event featuring boxer Mike Tyson, Tether CEO

April 26, 2026

Why Crypto’s Most Important Bill Is Stalling at 50/50 Odds Despite Presidential Backing

April 26, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»TeamTNT Targeted Cloud Instances and Containerized Environments For Two Years
TeamTNT Targeted Cloud Instances and Containerized Environments For Two Years
Security and Privacy

TeamTNT Targeted Cloud Instances and Containerized Environments For Two Years

June 14, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

The threat actor known as TeamTNT has been targeting cloud instances and containerized environments on systems around the world for at least two years.

The findings come from CloudSEK security researchers, who posted an advisory on Thursday detailing a timeline of TeamTNT attacks from February 2020 until July 2021.

According to the report, the group’s Github profile contains 25 public repositories, most of which are forks of popular red teaming tools and other repositories possibly utilized by them.

Additionally, the domain spotted by CloudSEK and allegedly associated with TeamTNT was registered on February 10, 2020, the same time period when the team began to target Redis servers actively. 

In these initial campaigns, CloudSEK said the aim of TeamTNT was cryptojacking, as the group deployed a number of tools typically used for these attacks, including pnscan, Tsunami and xmrigCC, among others.

TeamTNT then reportedly started attacking Docker instances in May 2020, mostly using the same cryptojacking-focussed tools but introducing the use of TCP port scanner masscan in conjunction with malicious Alpine images.

Throughout August 2020, the cybercriminal group continued their attacks on Docker, but they started using the Ubuntu images directly instead of Alpine. They also deployed the Linux Kernel Module (LKM) rootkit known as Diamorphine to hide their activities on infected machines.

Months later, they started exploiting Weavescope for troubleshooting and leveraging it as a backdoor, and in January 2021, a report by Lacework Labs suggested TeamTNT was using three new hacking tools targeting Kubernetes: Peirates, Botb, and libprocesshider.

In the second half of 2021, the group’s target list reportedly remained the same, but they expanded their credential-stealing capabilities to additional services and applications, including AWS, Filezilla and GitHub, among others. In July, TeamTNT launched a campaign named ‘Chimaera,’ suggesting the group continued their attacks on Docker, Kubernetes, and Weavescope services.

See also  Bare Metal Cloud Market: An In-Depth Analysis of Market Size, Share, Opportunities, Challenges, Demand, and Trends

At the time of writing, the domain associated with TeamTNT is now offline, but the CloudSEK advisory suggested some screenshots of the domain are still available on Wayback Machine.

The security researchers suggested the group most likely originated from Germany because most of the tweets and bash scripts (including comments) are in German, and the account’s location is set to ‘Deutschland’.

Source link

Cloud Containerized Environments Instances Targeted TeamTNT Years
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

For 93 minutes, installing Bitwarden’s ‘official’ CLI turned laptops into launchpads for hijacking GitHub accounts

April 24, 2026

Npm Supply Chain Attack Uses Worm-Like Propagation

April 24, 2026

How crypto futures markets are feeding ‘scam coin’ insider pump and dumps

April 21, 2026

Oil tanker attacked after falling for crypto scam granting fake Strait of Hormuz safe passage

April 21, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Guide to the MetalCore Ethereum Token

June 25, 2024

FDIC Chair Says Signature Bank Failed To Understand the Risks of Doing Business With Crypto Industry

May 21, 2023

Wow Bao Leaps into Metaverse with Innovative NFT Loyalty Program

May 26, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Olenox Announces Merge With CS Digital to Develop Low Cost, Off-Grid Bitcoin Mining Opportunities

April 26, 2026

Trump defends crypto legislation at private event featuring boxer Mike Tyson, Tether CEO

April 26, 2026

Why Crypto’s Most Important Bill Is Stalling at 50/50 Odds Despite Presidential Backing

April 26, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$77,472.00-0.20%
  • ethereumEthereum(ETH)$2,312.03-0.24%
  • tetherTether(USDT)$1.000.00%
  • rippleXRP(XRP)$1.42-1.06%
  • binancecoinBNB(BNB)$628.94-1.32%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$86.22-0.13%
  • tronTRON(TRX)$0.3237640.01%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.02-0.55%
  • dogecoinDogecoin(DOGE)$0.097583-1.18%