In the group’s latest attack routine, we found new evidence that TeamTNT has further extended its credential harvesting capabilities to target multiple cloud and non-cloud services in victims’ internal networks and systems post-compromise.
TeamTNT
TeamTNT is a Linux-focused cybercrime threat cluster best known for cloud and container intrusions that monetize access through unauthorized Monero mining and broad credential theft.
Profile source: Mallory opens in a new tabTeamTNT
Family profile
TeamTNT is a Linux-focused cybercrime threat cluster best known for cloud and container intrusions that monetize access through unauthorized Monero mining and broad credential theft. The group has repeatedly targeted exposed or weakly secured cloud-native infrastructure, including Docker environments and misconfigured container services, and has also exploited weak operational security such as exposed private keys, reused passwords, and cloud misconfigurations to gain access.
Its tooling and tradecraft center on Linux and containerized environments. TeamTNT has used malicious containers and abused exposed Docker REST APIs to deploy payloads, launch privileged containers, mount host filesystems, and pivot from containers to underlying hosts. Operations have included internet-scale scanning for additional exposed Docker services and enumeration of Kubernetes-related services, enabling worm-like propagation across cloud estates and adjacent systems.
A defining characteristic of TeamTNT activity is aggressive credential harvesting after compromise. The malware has searched compromised systems and connected environments for cloud and non-cloud service configuration files, application data, and stored credentials, including SSH and SMB credentials. It has also targeted Docker registry credentials and used harvested access to move laterally, automate logins, and potentially enable follow-on abuse such as cloud resource hijacking or supply-chain compromise. Collected data is exfiltrated to attacker-controlled infrastructure.
TeamTNT commonly relies on native Linux utilities and lightweight shell-based tooling for execution, discovery, persistence, and evasion. Observed behaviors include use of common command-line tools to download and execute payloads, inspect users and processes, alter cron-based persistence, clear shell history, and remove competing miners or traces of activity. The group has also used SSH-based propagation and techniques that facilitate container escape and host-level post-exploitation.
Although TeamTNT is frequently associated with cryptojacking, its operations extend beyond simple miner deployment. Campaigns have incorporated host reconnaissance, credential access, lateral movement, persistence, exfiltration, and post-compromise abuse of legitimate administration and monitoring technologies in container environments. TeamTNT is widely tracked as a significant Linux and cloud threat actor whose activity illustrates the convergence of cryptomining, credential theft, and cloud-native intrusion tradecraft.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Lateral Movement
- Persistence
- Post Exploitation
- Privilege Escalation
- Reconnaissance
- Scanning
Reported operators
Threat actors
1 named in public reportingExploited software
Vulnerabilities linked to TeamTNT
3 CVEsMITRE ATT&CK
TeamTNT in ATT&CK
1 distinct techniquesTechniques
1 techniqueReporting
Research mentioning TeamTNT
Threat news: TeamTNT stealing credentials using EC2 Instance Metadata | Sysdig
TeamTNT continued to evolve from a Linux-focused cryptojacking group into a broad cloud threat actor targeting exposed Redis, Docker, Kubernetes, Jupyter, Hadoop, PostgreSQL, Tomcat, Nginx, SSH, and other internet-facing services. Researchers tied the group to worm-like campaigns that rapidly scanned for vulnerable hosts, deployed XMRig miners, dropped Tsunami-based IRC bots including DDoS-capable variants, and used malicious container images on Docker Hub to spread payloads at scale. One TeamTNT-linked Docker Hub account reportedly served images pulled more than 150,000 times, while later campaigns showed the group abusing public registries, compromised accounts, and cloud-native tooling to infect newly exposed systems and report them back to command-and-control infrastructure. Across these operations, TeamTNT consistently paired monetization with aggressive credential theft and stealth. Investigations found the group harvesting AWS, Azure, GCP, Kubernetes, Git, NPM, Grafana, database, and storage secrets; stealing SSH keys and host data; and using tools such as Weave Scope, Peirates, BotB, MimiPenguin, Mimipy, tmate, and Gsocket to expand access and persistence. Analysts also documented detection evasion through log wiping, process hiding, LD_PRELOAD userland rootkits, the Diamorphine kernel rootkit, privileged containers with restart policies, and even disabling runc to lock out rival attackers, underscoring TeamTNT’s shift from opportunistic mining to sustained compromise of cloud and container environments.