Skip to content

TeamTNT

TeamTNT is a Linux-focused cybercrime threat cluster best known for cloud and container intrusions that monetize access through unauthorized Monero mining and broad credential theft.

Profile source: Mallory opens in a new tab

TeamTNT

Family profile

TeamTNT is a Linux-focused cybercrime threat cluster best known for cloud and container intrusions that monetize access through unauthorized Monero mining and broad credential theft. The group has repeatedly targeted exposed or weakly secured cloud-native infrastructure, including Docker environments and misconfigured container services, and has also exploited weak operational security such as exposed private keys, reused passwords, and cloud misconfigurations to gain access.

Its tooling and tradecraft center on Linux and containerized environments. TeamTNT has used malicious containers and abused exposed Docker REST APIs to deploy payloads, launch privileged containers, mount host filesystems, and pivot from containers to underlying hosts. Operations have included internet-scale scanning for additional exposed Docker services and enumeration of Kubernetes-related services, enabling worm-like propagation across cloud estates and adjacent systems.

A defining characteristic of TeamTNT activity is aggressive credential harvesting after compromise. The malware has searched compromised systems and connected environments for cloud and non-cloud service configuration files, application data, and stored credentials, including SSH and SMB credentials. It has also targeted Docker registry credentials and used harvested access to move laterally, automate logins, and potentially enable follow-on abuse such as cloud resource hijacking or supply-chain compromise. Collected data is exfiltrated to attacker-controlled infrastructure.

TeamTNT commonly relies on native Linux utilities and lightweight shell-based tooling for execution, discovery, persistence, and evasion. Observed behaviors include use of common command-line tools to download and execute payloads, inspect users and processes, alter cron-based persistence, clear shell history, and remove competing miners or traces of activity. The group has also used SSH-based propagation and techniques that facilitate container escape and host-level post-exploitation.

Although TeamTNT is frequently associated with cryptojacking, its operations extend beyond simple miner deployment. Campaigns have incorporated host reconnaissance, credential access, lateral movement, persistence, exfiltration, and post-compromise abuse of legitimate administration and monitoring technologies in container environments. TeamTNT is widely tracked as a significant Linux and cloud threat actor whose activity illustrates the convergence of cryptomining, credential theft, and cloud-native intrusion tradecraft.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance
  • Scanning

Reported operators

Threat actors

1 named in public reporting
TeamTNT

In the group’s latest attack routine, we found new evidence that TeamTNT has further extended its credential harvesting capabilities to target multiple cloud and non-cloud services in victims’ internal networks and systems post-compromise.

Exploited software

Vulnerabilities linked to TeamTNT

3 CVEs

MITRE ATT&CK

TeamTNT in ATT&CK

1 distinct techniques

Reporting

Research mentioning TeamTNT

Jul 31
Sysdig

Threat news: TeamTNT stealing credentials using EC2 Instance Metadata | Sysdig

TeamTNT continued to evolve from a Linux-focused cryptojacking group into a broad cloud threat actor targeting exposed Redis, Docker, Kubernetes, Jupyter, Hadoop, PostgreSQL, Tomcat, Nginx, SSH, and other internet-facing services. Researchers tied the group to worm-like campaigns that rapidly scanned for vulnerable hosts, deployed XMRig miners, dropped Tsunami-based IRC bots including DDoS-capable variants, and used malicious container images on Docker Hub to spread payloads at scale. One TeamTNT-linked Docker Hub account reportedly served images pulled more than 150,000 times, while later campaigns showed the group abusing public registries, compromised accounts, and cloud-native tooling to infect newly exposed systems and report them back to command-and-control infrastructure. Across these operations, TeamTNT consistently paired monetization with aggressive credential theft and stealth. Investigations found the group harvesting AWS, Azure, GCP, Kubernetes, Git, NPM, Grafana, database, and storage secrets; stealing SSH keys and host data; and using tools such as Weave Scope, Peirates, BotB, MimiPenguin, Mimipy, tmate, and Gsocket to expand access and persistence. Analysts also documented detection evasion through log wiping, process hiding, LD_PRELOAD userland rootkits, the Diamorphine kernel rootkit, privileged containers with restart policies, and even disabling runc to lock out rival attackers, underscoring TeamTNT’s shift from opportunistic mining to sustained compromise of cloud and container environments.

Apr 14
Mitre Attack Website

Matrix - Enterprise - Containers | MITRE ATT&CK®

Jan 1
Intezer

Abusing Legitimate Cloud Monitoring Tools for Cyber Attacks - Intezer

Jan 1
Intezer

TeamTNT Cryptomining Explosion 🧨 - Intezer

Sep 11
Group Ib

Storm clouds on the horizon: Resurgence of TeamTNT? | Group-IB Blog

Jul 13
Aquasec Other

TeamTNT Reemerged with New Aggressive Cloud Campaign

Sep 15
Aquasec

Threat Alert: New Malware in the Cloud By TeamTNT

Sep 12
Trend Micro Research

Security Breaks: TeamTNT’s DockerHub Credentials Leak | Trend Micro (US)

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.