TeamTNT
MITRE ATT&CK: G0139 View on attack.mitre.org
Aliases: Adept Libra, TeamTNT
- First seen
- 2019-10-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- team
- Actor type
- criminal
- Related IoCs
- 9 (7 malicious)
- Last IoC activity
- 2026-09-01 16:37:39
- Profile updated
- 2026-07-07 11:59:41
Targeted industries: technology-and-telecommunications financial-services energy-and-utilities
Context
TeamTNT is a threat group that has primarily targeted cloud and containerized environments. The group as been active since at least October 2019 and has mainly focused its efforts on leveraging cloud and container resources to deploy cryptocurrency miners in victim environments.
Recent IoC activity
7 malicious indicators in Maltiverse are attributed to TeamTNT (G0139). The 7 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | donaldtrump.cc | 2026-09-02 | 1 |
| hostname | teamtnt.red | 2026-09-02 | 4 |
| file sample | 6075906fbc8898515fe09a046d81ca66429c9b3052a13d6b3ca6f8294c70d207 | 2026-07-21 | 2 |
| file sample | 4aad141a34ad328580f1d4925007bfd675bb5ca7888c23a3a4b77661f31081ee | 2026-05-28 | 1 |
| hostname | solscan.one | 2025-10-27 | 1 |
| hostname | solscan.life | 2025-10-15 | 1 |
| hostname | devnull.anondns.net | 2025-06-18 | 1 |
Detection coverage
- 2 YARA rules
- 882 Sigma rules
Malware & tools used
- Remote Access Tools (attack-pattern)
- Systemctl (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Linux and Mac Permissions (attack-pattern)
- File Deletion (attack-pattern)
- Container Administration Command (attack-pattern)
- Unix Shell (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Systemd Service (attack-pattern)
- Local Account (attack-pattern)
- System Service Discovery (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Windows Service (attack-pattern)
- Upload Malware (attack-pattern)
- Windows Command Shell (attack-pattern)
- Deploy Container (attack-pattern)
- Container and Resource Discovery (attack-pattern)
- Exfiltration Over Alternative Protocol (attack-pattern)
- Process Discovery (attack-pattern)
- PowerShell (attack-pattern)
- Cloud Instance Metadata API (attack-pattern)
- Clear Command History (attack-pattern)
- Local Data Staging (attack-pattern)
- Vulnerability Scanning (attack-pattern)
- Container CLI/API (attack-pattern)
Reports & references
- Palo Alto Unit 42 — Hildegard Malware Teamtnt (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Teamtnt (report)
- blog.aquasec.com — Teamtnt Campaign Against Docker Kubernetes Environment (report)
- cybersecurity.att.com — Teamtnt Delivers Malware With New Detection Evasion Tool (report)
- cadosecurity.com — Team Tnt The First Crypto Mining Worm To Steal Aws Credentials (report)
- intezer.com — Top Linux Cloud Threats Of 2020 (report)
- Trend Micro — Teamtnt Now Deploying Ddos Capable Irc Bot Tntbotinger (report)
- cyware.com — Hildegard Teamtnts New Feature Rich Malware Targeting Kubernetes 6587Eb45 (report)
- lacework.com — Teamtnt Builds Botnet From Chinese Cloud Servers (report)
- Palo Alto Unit 42 — Adept Libra (report)
- MITRE ATT&CK — G0139 (report)
- blog.aquasec.com — Container Security Tnt Container Attack (report)
- cybersecurity.att.com — Teamtnt With New Campaign Aka Chimaera (report)
- Trend Micro — Wp Tracking The Activities Of Teamtnt (report)
- Palo Alto Unit 42 — Black T Cryptojacking Variant (report)
- cadosecurity.com — Team Tnt The First Crypto Mining Worm To Steal Aws Credentials (report)
- intezer.com — Attackers Abusing Legitimate Cloud Monitoring Tools To Conduct Cyber Attacks (report)
- intezer.com — Teamtnt Cryptomining Explosion (report)
- lacework.com — Taking Teamtnt Docker Images Offline (report)
External references
- mitre-attack — G0139
- ATT TeamTNT Chimaera September 2020
- Cado Security TeamTNT Worm August 2020
- Unit 42 Hildegard Malware
- Trend Micro TeamTNT
- Intezer TeamTNT September 2020
- Intezer TeamTNT Explosion September 2021
- Aqua TeamTNT August 2020
- Palo Alto Black-T October 2020
- Lacework TeamTNT May 2021
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy