TeamTNT

MITRE ATT&CK: G0139 View on attack.mitre.org

Aliases: Adept Libra, TeamTNT

First seen
2019-10-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
team
Actor type
criminal
Related IoCs
9 (7 malicious)
Last IoC activity
2026-09-01 16:37:39
Profile updated
2026-07-07 11:59:41

Targeted industries: technology-and-telecommunications financial-services energy-and-utilities

Context

TeamTNT is a threat group that has primarily targeted cloud and containerized environments. The group as been active since at least October 2019 and has mainly focused its efforts on leveraging cloud and container resources to deploy cryptocurrency miners in victim environments.

Recent IoC activity

7 malicious indicators in Maltiverse are attributed to TeamTNT (G0139). The 7 most recently updated:

TypeIndicatorUpdatedSources
hostname donaldtrump.cc 2026-09-02 1
hostname teamtnt.red 2026-09-02 4
file sample 6075906fbc8898515fe09a046d81ca66429c9b3052a13d6b3ca6f8294c70d207 2026-07-21 2
file sample 4aad141a34ad328580f1d4925007bfd675bb5ca7888c23a3a4b77661f31081ee 2026-05-28 1
hostname solscan.one 2025-10-27 1
hostname solscan.life 2025-10-15 1
hostname devnull.anondns.net 2025-06-18 1

Detection coverage

  • 2 YARA rules
  • 882 Sigma rules

Malware & tools used

  • Remote Access Tools (attack-pattern)
  • Systemctl (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Linux and Mac Permissions (attack-pattern)
  • File Deletion (attack-pattern)
  • Container Administration Command (attack-pattern)
  • Unix Shell (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Systemd Service (attack-pattern)
  • Local Account (attack-pattern)
  • System Service Discovery (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Windows Service (attack-pattern)
  • Upload Malware (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Deploy Container (attack-pattern)
  • Container and Resource Discovery (attack-pattern)
  • Exfiltration Over Alternative Protocol (attack-pattern)
  • Process Discovery (attack-pattern)
  • PowerShell (attack-pattern)
  • Cloud Instance Metadata API (attack-pattern)
  • Clear Command History (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Vulnerability Scanning (attack-pattern)
  • Container CLI/API (attack-pattern)

Reports & references

  • Palo Alto Unit 42 — Hildegard Malware Teamtnt (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Teamtnt (report)
  • blog.aquasec.com — Teamtnt Campaign Against Docker Kubernetes Environment (report)
  • cybersecurity.att.com — Teamtnt Delivers Malware With New Detection Evasion Tool (report)
  • cadosecurity.com — Team Tnt The First Crypto Mining Worm To Steal Aws Credentials (report)
  • intezer.com — Top Linux Cloud Threats Of 2020 (report)
  • Trend Micro — Teamtnt Now Deploying Ddos Capable Irc Bot Tntbotinger (report)
  • cyware.com — Hildegard Teamtnts New Feature Rich Malware Targeting Kubernetes 6587Eb45 (report)
  • lacework.com — Teamtnt Builds Botnet From Chinese Cloud Servers (report)
  • Palo Alto Unit 42 — Adept Libra (report)
  • MITRE ATT&CK — G0139 (report)
  • blog.aquasec.com — Container Security Tnt Container Attack (report)
  • cybersecurity.att.com — Teamtnt With New Campaign Aka Chimaera (report)
  • Trend Micro — Wp Tracking The Activities Of Teamtnt (report)
  • Palo Alto Unit 42 — Black T Cryptojacking Variant (report)
  • cadosecurity.com — Team Tnt The First Crypto Mining Worm To Steal Aws Credentials (report)
  • intezer.com — Attackers Abusing Legitimate Cloud Monitoring Tools To Conduct Cyber Attacks (report)
  • intezer.com — Teamtnt Cryptomining Explosion (report)
  • lacework.com — Taking Teamtnt Docker Images Offline (report)

External references