All actors

TeamTNT

Also reported as Adept Libra.

Reports
114
Last reported
Known CVEs
63
Techniques in ATT&CK
56
ID
G0139
Merge evidence
3 alias matches

Reports per quarter

  1. 2007 Q4: 1 report
  2. 2008 Q1: no reports
  3. 2008 Q2: no reports
  4. 2008 Q3: no reports
  5. 2008 Q4: no reports
  6. 2009 Q1: no reports
  7. 2009 Q2: no reports
  8. 2009 Q3: no reports
  9. 2009 Q4: no reports
  10. 2010 Q1: no reports
  11. 2010 Q2: no reports
  12. 2010 Q3: no reports
  13. 2010 Q4: no reports
  14. 2011 Q1: no reports
  15. 2011 Q2: no reports
  16. 2011 Q3: no reports
  17. 2011 Q4: no reports
  18. 2012 Q1: no reports
  19. 2012 Q2: no reports
  20. 2012 Q3: 2 reports
  21. 2012 Q4: 2 reports
  22. 2013 Q1: no reports
  23. 2013 Q2: no reports
  24. 2013 Q3: 1 report
  25. 2013 Q4: no reports
  26. 2014 Q1: 1 report
  27. 2014 Q2: 2 reports
  28. 2014 Q3: 1 report
  29. 2014 Q4: no reports
  30. 2015 Q1: 1 report
  31. 2015 Q2: no reports
  32. 2015 Q3: no reports
  33. 2015 Q4: 1 report
  34. 2016 Q1: 1 report
  35. 2016 Q2: no reports
  36. 2016 Q3: 1 report
  37. 2016 Q4: no reports
  38. 2017 Q1: no reports
  39. 2017 Q2: no reports
  40. 2017 Q3: no reports
  41. 2017 Q4: 1 report
  42. 2018 Q1: 1 report
  43. 2018 Q2: no reports
  44. 2018 Q3: no reports
  45. 2018 Q4: 2 reports
  46. 2019 Q1: 2 reports
  47. 2019 Q2: no reports
  48. 2019 Q3: no reports
  49. 2019 Q4: 4 reports
  50. 2020 Q1: 6 reports
  51. 2020 Q2: no reports
  52. 2020 Q3: 9 reports
  53. 2020 Q4: 8 reports
  54. 2021 Q1: 12 reports
  55. 2021 Q2: 5 reports
  56. 2021 Q3: 6 reports
  57. 2021 Q4: 15 reports
  58. 2022 Q1: 4 reports
  59. 2022 Q2: 3 reports
  60. 2022 Q3: 6 reports
  61. 2022 Q4: 1 report
  62. 2023 Q1: no reports
  63. 2023 Q2: no reports
  64. 2023 Q3: 4 reports
  65. 2023 Q4: no reports
  66. 2024 Q1: no reports
  67. 2024 Q2: no reports
  68. 2024 Q3: 1 report
  69. 2024 Q4: no reports
  70. 2025 Q1: no reports
  71. 2025 Q2: no reports
  72. 2025 Q3: no reports
  73. 2025 Q4: no reports
  74. 2026 Q1: no reports
  75. 2026 Q2: 10 reports
Dated reports, 2007 Q4 to 2026 Q2.

Techniques seen in the last two years

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

Show all 54 techniques Show fewer

CVEs named in reports

Show all 63 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. elf.wellmess (Malware Family)

    date ORKL added it fromORKL

Show all 114 reports Show fewer
  1. Threat Horizons - September 2022

    file creation date Google's Cybersecurity Action Team (GCAT) fromORKL

  2. Threat Alert- New Malware in the Cloud By TeamTNT

    date in the title fromORKL

  3. Security Breaks- TeamTNT’s DockerHub Credentials Leak

    date in the title fromORKL

  4. How Malicious Actors Abuse Native Linux Tools in Attacks

    date in the title fromORKL

  5. 2017-12 - Nine circles of Cerber

    file creation date fromORKL

  6. TeamTNT Cryptomining Explosion

    date in the title fromORKL

  7. Analyzing How TeamTNT Used Compromised Docker Hub Accounts

    date in the title fromORKL

  8. Groups Target Alibaba ECS Instances for Cryptojacking

    date in the title fromORKL

  9. TeamTNT Continues to Target Exposed Docker API

    date in the title fromORKL

  10. Team TNT Deploys Malicious Docker Image On Docker Hub

    date in the title fromORKL

  11. TeamTNT Script Employed to Grab AWS Credentials

    date in the title fromORKL

  12. TeamTNT with new campaign aka “Chimaera”

    date in the title fromORKL

  13. TeamTNT-Cryptomining-Explosion.pdf

    Malpedia library date fromORKL

  14. The “Kek Security” Network

    date in the title fromORKL

  15. Malpedia Website for Malware Family Team TNT

    date in the title fromORKL

  16. TeamTNT (Malware Family)

    Malpedia library date fromORKL

  17. Hildegard_ New TeamTNT Malware Targeting Kubernetes

    date in the CCS '25 data Palo Alto fromORKLCCS '25 data

  18. Hildegard- New TeamTNT Malware Targeting Kubernetes

    date in the title fromORKL

  19. TeamTNT delivers malware with new detection evasion tool

    date in the title fromORKL

  20. Botnet Deploys Cloud and Container Attack Techniques

    date in the title fromORKL

  21. Malware using new Ezuri memory loader

    date in the title fromORKL

  22. Investigating Crimeware Name Servers

    date in the title fromORKL

  23. TeamTNT Now Deploying DDoS-Capable IRC Bot TNTbotinger

    date in the title fromORKL

  24. Threat Alert- Fileless Malware Executing in Containers

    date in the title fromORKL

  25. Black-T- New Cryptojacking Variant from TeamTnT

    date in the title fromORKL

  26. TeamTNT activity targets Weave Scope deployments

    date in the title fromORKL

  27. Cetus- Cryptojacking Worm Targeting Docker Daemons

    date in the title fromORKL

  28. Kimsuky group- tracking the king of the spear phishing

    date in the title fromORKL

  29. LokiBot- dissecting the C&C panel deployments

    date in the title fromORKL

  30. Behind the scenes of GandCrab’s operation

    date in the title fromORKL

  31. Spoofing in the reeds with Rietspoof

    date in the title fromORKL

  32. APT15

    date in the CCS '25 data Intezer fromCCS '25 data

  33. From Hacking Team to hacked team to...-

    date in the title fromORKL

  34. VB2018 - Inside Formbook InfoStealer

    date in the title fromORKL

  35. Tracking Mirai Variants (Ya Liu & Hui Wang)

    date in the title fromORKL

  36. VB2018 - Who Was Not Responsible for Olympic Destroyer

    date in the title fromORKL

  37. KeyBase - A New Keylogger on the Block

    date in the title fromORKL

  38. Shifu – the rise of a self-destructive banking trojan

    date in the title fromORKL

  39. VB2014 paper- The pluginer - Caphaw

    date in the title fromORKL

  40. Bird's nest

    date in the title fromORKL

  41. Sinowal banking trojan

    date in the title fromORKL

  42. Tofsee botnet

    date in the title fromORKL

  43. Needle in a haystack

    date in the title fromORKL

  44. Andromeda 2.7 features

    date in the title fromORKL

  45. Compromised library

    date in the title fromORKL

  46. Tracking the 2012 Sasfis campaign

    date in the title fromORKL

  47. URLZone reloaded- new evolution

    date in the title fromORKL

  48. Inside the ICE IX bot, descendent of Zeus

    date in the title fromORKL

  49. Spam from the kernel

    date in the title fromORKL

Newest first. Details opens the report in Explore.