TeamTNT

First seen
2019-09-01 00:00:00
Malware type
cryptominer
Family
Malware family
Last IoC activity
2026-07-21 18:53:33
Profile updated
2026-07-07 12:58:57

Targeted industries: technology-and-telecommunications energy-and-utilities

Context

Since Fall 2019, Team TNT is a well known threat actor which targets *nix based systems and misconfigured Docker container environments. It has constantly evolved its capabilities for its cloud-based cryptojacking operations. They have shifted their focus on compromising Kubernetes Clusters.

Reports & references

  • Palo Alto Unit 42 — Hildegard Malware Teamtnt (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Teamtnt (report)
  • blog.aquasec.com — Teamtnt Campaign Against Docker Kubernetes Environment (report)
  • cybersecurity.att.com — Teamtnt Delivers Malware With New Detection Evasion Tool (report)
  • cadosecurity.com — Team Tnt The First Crypto Mining Worm To Steal Aws Credentials (report)
  • intezer.com — Top Linux Cloud Threats Of 2020 (report)
  • lacework.com — Teamtnt Builds Botnet From Chinese Cloud Servers (report)
  • Palo Alto Unit 42 — Adept Libra (report)
  • Palo Alto Unit 42 — Thieflibra (report)
  • cybersecurity.att.com — Teamtnt With New Campaign Aka Chimaera (report)
  • Trend Micro — Wp Tracking The Activities Of Teamtnt (report)
  • intezer.com — Teamtnt Cryptomining Explosion (report)
  • vmware.com — Vmw Exposing Malware In Linux Based Multi Cloud Environments (report)
  • cyberark.com — Conti Group Leaked (report)
  • sysdig.com — Teamtnt Aws Credentials (report)
  • aquasec.com — Fileless Malware Container Security (report)
  • Trend Micro — More Tools In The Arsenal How Teamtnt Used Compromised Docker Hu (report)
  • cadosecurity.com — Teamtnt The First Crypto Mining Worm To Steal Aws Credentials (report)
  • Trend Micro — Teamtnt Upgrades Arsenal Refines Focus On Kubernetes And Gpu Env (report)
  • cadosecurity.com — Teamtnt Script Employed To Grab Aws Credentials (report)
  • intezer.com — Teamtnt Cryptomining Explosion (report)
  • tolisec.com — Active Crypto Mining Operation By Teamtnt (report)
  • aquasec.com — Container Security Tnt Container Attack (report)
  • aquasec.com — Threat Alert Anatomy Of Silentbobs Cloud Attack (report)
  • uptycs.com — Team Tnt Deploys Malicious Docker Image On Docker Hub With Pentesting Tools (report)

External references