TeamTNT
Also reported as Adept Libra.
Reports per quarter
Techniques seen in the last two years
- T1003.008 1 report reports only
- T1027 1 report reports only
- T1053.003 1 report reports only
- T1057 1 report in ATT&CK
- T1098.004 1 report in ATT&CK
- T1480 1 report reports only
- T1496 1 report reports only
- T1547 1 report reports only
- T1564.001 1 report reports only
- T1592.002 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
Show all 54 techniques Show fewer
- T1059.003
- T1059.004
- T1059.009
- T1059.013
- T1070.003
- T1070.004
- T1071
- T1071.001
- T1074.001
- T1082
- T1083
- T1102
- T1105
- T1120
- T1133
- T1136.001
- T1140
- T1204.003
- T1219
- T1222.002
- T1496.001
- T1518.001
- T1543.002
- T1543.003
- T1547.001
- T1552.001
- T1552.004
- T1552.005
- T1569.003
- T1583.001
- T1587.001
- T1595.001
- T1595.002
- T1608.001
- T1609
- T1610
- T1611
- T1613
- T1680
- T1685
- T1685.006
- T1686
CVEs named in reports
- CVE-2003-1138
- CVE-2005-1380
- CVE-2010-0817
- CVE-2010-1424
- CVE-2010-2152
- CVE-2010-3915
- CVE-2010-3916
- CVE-2010-3936
- CVE-2011-1264
- CVE-2011-1331
- CVE-2011-3544 KEV
- CVE-2012-0158 KEV ransomware
Show all 63 CVEs Show fewer
- CVE-2013-0707
- CVE-2013-3644
- CVE-2013-3893 KEV
- CVE-2013-3918 KEV
- CVE-2013-5990
- CVE-2014-0810
- CVE-2014-1761 KEV
- CVE-2014-3567
- CVE-2014-4113 KEV
- CVE-2014-6271 KEV
- CVE-2014-6277
- CVE-2014-6278 KEV
- CVE-2014-6324 KEV
- CVE-2014-7247
- CVE-2015-0003
- CVE-2015-7645 KEV ransomware
- CVE-2016-1019 KEV ransomware
- CVE-2016-4117 KEV ransomware
- CVE-2016-7836 KEV
- CVE-2017-0068
- CVE-2017-0199 KEV ransomware
- CVE-2017-11882 KEV ransomware
- CVE-2017-14100
- CVE-2017-5638 KEV ransomware
- CVE-2017-8570 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-10562 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2018-20781
- CVE-2018-8570
- CVE-2019-1002100
- CVE-2019-11510 KEV ransomware
- CVE-2019-11539 KEV ransomware
- CVE-2019-1225
- CVE-2019-1579 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-2725 KEV ransomware
- CVE-2019-5736
- CVE-2020-14882 KEV
- CVE-2020-5902 KEV ransomware
- CVE-2021-21973 KEV
- CVE-2021-22893 KEV ransomware
- CVE-2021-22986 KEV ransomware
- CVE-2021-26084 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-30116 KEV ransomware
- CVE-2021-3129 KEV ransomware
- CVE-2021-34473 KEV ransomware
- CVE-2021-44228 KEV ransomware
- CVE-2022-0543 KEV
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Cloud-Native Application Protection Platform (CNAPP)
The original link failed its last check. Original publisher Detailsfor Cloud-Native Application Protection Platform (CNAPP)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor elf.wellmess (Malware Family)
Show all 114 reports Show fewer
-
Threat Alert- New Malware in the Cloud By TeamTNT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Alert- New Malware in the Cloud By TeamTNT
-
Security Breaks- TeamTNT’s DockerHub Credentials Leak
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Security Breaks- TeamTNT’s DockerHub Credentials Leak
-
How Malicious Actors Abuse Native Linux Tools in Attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor How Malicious Actors Abuse Native Linux Tools in Attacks
-
Alibaba OSS Buckets Compromised to Distribute Malicious Shell Scripts via Steganography
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Alibaba OSS Buckets Compromised to Distribute Malicious Shell Scripts via Steganography
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 2019-10 - Geost botnet. The story of the discovery of a new Android banking trojan from an OpSec error
-
2017-12 - Nine circles of Cerber
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 2017-12 - Nine circles of Cerber
-
Cryptojacking on the Fly- TeamTNT Using NVIDIA Drivers to Mine Cryptocurrency
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cryptojacking on the Fly- TeamTNT Using NVIDIA Drivers to Mine Cryptocurrency
-
TeamTNT Cryptomining Explosion
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TeamTNT Cryptomining Explosion
-
VMware Exposing Malware In Linux Based Multi Cloud Environments
The original link failed its last check. Original publisher Detailsfor VMware Exposing Malware In Linux Based Multi Cloud Environments
-
Collector-stealer- a Russian origin credential and information extractor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Collector-stealer- a Russian origin credential and information extractor
-
Threat news- TeamTNT stealing credentials using EC2 Instance Metadata
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat news- TeamTNT stealing credentials using EC2 Instance Metadata
-
Analyzing How TeamTNT Used Compromised Docker Hub Accounts
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analyzing How TeamTNT Used Compromised Docker Hub Accounts
-
Groups Target Alibaba ECS Instances for Cryptojacking
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Groups Target Alibaba ECS Instances for Cryptojacking
-
TeamTNT Upgrades Arsenal, Refines Focus on Kubernetes and GPU Environments
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TeamTNT Upgrades Arsenal, Refines Focus on Kubernetes and GPU Environments
-
Compromised Docker Hub Accounts Abused for Cryptomining Linked to TeamTNT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Compromised Docker Hub Accounts Abused for Cryptomining Linked to TeamTNT
-
TeamTNT Upgrades Arsenal, Refines Focus on Kubernetes and GPU Environments
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TeamTNT Upgrades Arsenal, Refines Focus on Kubernetes and GPU Environments
-
TeamTNT Continues to Target Exposed Docker API
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TeamTNT Continues to Target Exposed Docker API
-
Team TNT Deploys Malicious Docker Image On Docker Hub
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Team TNT Deploys Malicious Docker Image On Docker Hub
-
Inside TeamTNT’s Impressive Arsenal- A Look Into A TeamTNT Server
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Inside TeamTNT’s Impressive Arsenal- A Look Into A TeamTNT Server
-
TeamTNT Script Employed to Grab AWS Credentials
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TeamTNT Script Employed to Grab AWS Credentials
-
Archived copy on ORKL Detailsfor AquaSecurity_Cloud_Native_Threat_Report_2021.pdf?utm_campaign=WP%20-%20Jun2021%20Nautilus%202021%20Threat%20Research%20Report&utm_medium=email&_hsmi=132931006&_hsenc=p2ANqtz-_8oopT5Uhqab8B7kE0l3iFo1koirxtyfTehxF7N-EdGYrwk30gfiwp5SiNlW3G0TNKZxUcDkYOtwQ9S6nNVNyEO-Dgrw&utm_content=132931006&utm_source=hs_automation
-
TeamTNT with new campaign aka “Chimaera”
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TeamTNT with new campaign aka “Chimaera”
-
TeamTNT-Cryptomining-Explosion.pdf
The original link failed its last check. Original publisher Detailsfor TeamTNT-Cryptomining-Explosion.pdf
-
Tracking the Activities of TeamTNT: A Closer Look at a Cloud-Focused Malicious Actor Group
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Tracking the Activities of TeamTNT: A Closer Look at a Cloud-Focused Malicious Actor Group
-
TeamTNT Using WatchDog TTPs to Expand Its Cryptojacking Footprint
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TeamTNT Using WatchDog TTPs to Expand Its Cryptojacking Footprint
-
TeamTNT Actively Enumerating Cloud Environments to Infiltrate Organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TeamTNT Actively Enumerating Cloud Environments to Infiltrate Organizations
-
TeamTNT Targets Kubernetes, Nearly 50,000 IPs Compromised in Worm-like Attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TeamTNT Targets Kubernetes, Nearly 50,000 IPs Compromised in Worm-like Attack
-
TeamTNT’s Extended Credential Harvester Targets Cloud Services, Other Software
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TeamTNT’s Extended Credential Harvester Targets Cloud Services, Other Software
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The “Kek Security” Network
-
Malpedia Website for Malware Family Team TNT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malpedia Website for Malware Family Team TNT
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor TeamTNT (Malware Family)
-
Threat Alert- TeamTNT Pwn Campaign Against Docker and K8s Environments
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Alert- TeamTNT Pwn Campaign Against Docker and K8s Environments
-
Hildegard- TeamTNT’s New Feature-Rich Malware Targeting Kubernetes
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hildegard- TeamTNT’s New Feature-Rich Malware Targeting Kubernetes
-
Hildegard_ New TeamTNT Malware Targeting Kubernetes
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Hildegard_ New TeamTNT Malware Targeting Kubernetes
-
Hildegard- New TeamTNT Malware Targeting Kubernetes
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hildegard- New TeamTNT Malware Targeting Kubernetes
-
TeamTNT delivers malware with new detection evasion tool
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TeamTNT delivers malware with new detection evasion tool
-
Botnet Deploys Cloud and Container Attack Techniques
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Botnet Deploys Cloud and Container Attack Techniques
-
Malware using new Ezuri memory loader
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malware using new Ezuri memory loader
-
Investigating Crimeware Name Servers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Investigating Crimeware Name Servers
-
TeamTNT Now Deploying DDoS-Capable IRC Bot TNTbotinger
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TeamTNT Now Deploying DDoS-Capable IRC Bot TNTbotinger
-
Threat Alert- Fileless Malware Executing in Containers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Alert- Fileless Malware Executing in Containers
-
Black-T- New Cryptojacking Variant from TeamTnT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Black-T- New Cryptojacking Variant from TeamTnT
-
TeamTNT activity targets Weave Scope deployments - Microsoft Tech Community - 1645968
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor TeamTNT activity targets Weave Scope deployments - Microsoft Tech Community - 1645968
-
TeamTNT activity targets Weave Scope deployments
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TeamTNT activity targets Weave Scope deployments
-
Attackers Abusing Legitimate Cloud Monitoring Tools to Conduct Cyber Attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attackers Abusing Legitimate Cloud Monitoring Tools to Conduct Cyber Attacks
-
Cetus- Cryptojacking Worm Targeting Docker Daemons
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cetus- Cryptojacking Worm Targeting Docker Daemons
-
Team TNT – The First Crypto-Mining Worm to Steal AWS Credentials
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Team TNT – The First Crypto-Mining Worm to Steal AWS Credentials
-
Team TNT - The First Crypto-Mining Worm to Steal AWS Credentials
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Team TNT - The First Crypto-Mining Worm to Steal AWS Credentials
-
Attribution is in the object- using RTF object dimensions to track APT phishing weaponizers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attribution is in the object- using RTF object dimensions to track APT phishing weaponizers
-
Kimsuky group- tracking the king of the spear phishing
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Kimsuky group- tracking the king of the spear phishing
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Pulling the PKPLUG- the adversary playbook for the long-standing espionage activity of a Chinese nation-state adversary
-
LokiBot- dissecting the C&C panel deployments
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor LokiBot- dissecting the C&C panel deployments
-
Rich Headers- leveraging this mysterious artifact of the PE format
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Rich Headers- leveraging this mysterious artifact of the PE format
-
Behind the scenes of GandCrab’s operation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Behind the scenes of GandCrab’s operation
-
Cyber espionage in the Middle East- unravelling OSX.WindTail
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber espionage in the Middle East- unravelling OSX.WindTail
-
APT cases exploiting vulnerabilities in region‑specific software
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT cases exploiting vulnerabilities in region‑specific software
-
Spoofing in the reeds with Rietspoof
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Spoofing in the reeds with Rietspoof
-
The original link failed its last check. Detailsfor APT15
-
From Hacking Team to hacked team to...-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor From Hacking Team to hacked team to...-
-
VB2018 - Inside Formbook InfoStealer
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor VB2018 - Inside Formbook InfoStealer
-
Tracking Mirai Variants (Ya Liu & Hui Wang)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tracking Mirai Variants (Ya Liu & Hui Wang)
-
VB2018 - Who Was Not Responsible for Olympic Destroyer
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor VB2018 - Who Was Not Responsible for Olympic Destroyer
-
A review of the evolution of Andromeda over the years before we say goodbye
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A review of the evolution of Andromeda over the years before we say goodbye
-
VB2017 - Offensive Malware Analysis - Dissecting OSX-FruitFly.B Via a Custom C&C Server
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor VB2017 - Offensive Malware Analysis - Dissecting OSX-FruitFly.B Via a Custom C&C Server
-
KeyBase - A New Keylogger on the Block
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor KeyBase - A New Keylogger on the Block
-
VB2015 paper- It's A File Infector... It’s Ransomware... It's Virlock
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor VB2015 paper- It's A File Infector... It’s Ransomware... It's Virlock
-
Shifu – the rise of a self-destructive banking trojan
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Shifu – the rise of a self-destructive banking trojan
-
VB2014 paper- The pluginer - Caphaw
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor VB2014 paper- The pluginer - Caphaw
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Bird's nest
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sinowal banking trojan
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tofsee botnet
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Needle in a haystack
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Andromeda 2.7 features
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Compromised library
-
Tracking the 2012 Sasfis campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tracking the 2012 Sasfis campaign
-
URLZone reloaded- new evolution
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor URLZone reloaded- new evolution
-
Inside the ICE IX bot, descendent of Zeus
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Inside the ICE IX bot, descendent of Zeus
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Spam from the kernel
Newest first. Details opens the report in Explore.