Home/Threat Actor/TeamTNT (Cloud Cryptojacking Operator)
Threat Actor

TeamTNT (Cloud Cryptojacking Operator)

teamtnt · financially_motivated_cybercrime_cloud_native_cryptojacking_specialist_german_speaking_indicators · active since 2019-01

TeamTNT is a financially-motivated cybercrime group specializing in cloud-native environment exploitation for cryptojacking active since at least 2019 with German-speaking actor attribution indicators per Aqua Security analysis ("Aqua Security linked the new campaign to the group via the Tsunami malware it commonly used, use of the dAPIpwn function and a C2 server that replies in German") + Docker REST API + Kubernetes + JupyterLab misconfiguration exploitation specialization + DockerHub abuse via alpineos account distributing malicious container images + Tsunami IRC-based DDoS backdoor + Diamorphine Linux kernel module rootkit + XMRig Monero coinminer + Sliver C2 framework multi-malware toolset + 2024 Chimaera (September) + Docker Gatling Gun (October) campaign resurgence with Docker Swarm enlistment + renting-breached- servers-to-third-parties business model evolution; financially-motivated cybercrime attribution per Aqua Security canonical multi-year tracking + Trend Micro / Nitesh Surana canonical Docker REST API exploitation analysis ("The threat actors found the misconfiguration and exploited it thrice from IPs based in Germany, where they were logged in to their DockerHub registry... the motivation of the attacker was to exploit the Docker REST API and compromise the underlying server to perform cryptojacking") + Datadog Security Labs 2024 Docker Swarm + Kubernetes cryptojacking campaign tracking + Cyjax MITRE ATT&CK Framework addition + Group-IB October 2024 observation + Wiz Cloud Threat Landscape canonical cloud-fluent threat actor designation + Cybersec Sentinel + The Hacker News + Infosecurity Magazine multi-vendor industry consensus.

honest attribution caveat 2024 resurgence attribution to TeamTNT is via code similarity + tradecraft pattern (Tsunami malware + dAPIpwn function + German-language C2 server responses)

Aqua Security acknowledges possibility of "advanced copycat" emulating TeamTNT code as alternative attribution ("similar to a similarly sophisticated group capable of emulating TeamTNT code and which has a 'distinct sense of humor' and 'affinity for the Dutch language'")

standalone cluster paralleling unc1860 + unc4990 + confucius in v0.1.178 heterogeneous nation-state + criminal cluster gap-filler cell.

operational target profile signature misconfigured Docker REST API endpoints + exposed Kubernetes API servers + misconfigured JupyterLab servers + CentOS VPS instances + opportunistic global targeting (financially-motivated no industry/geography focus)

operational attack architecture: (1) cluster-defining cloud-native cryptojacking specialization with Docker + Kubernetes + cloud-native infrastructure focus distinguishing from traditional enterprise-focused cybercrime actors.

(2) cluster-defining Docker REST API + Kubernetes + JupyterLab misconfiguration exploitation signature with exposed API endpoints as primary infection vectors.

(3) cluster-defining DockerHub alpineos account malicious container image distribution tradecraft abusing DockerHub free Container Registry services to distribute payloads including coin miners + rootkits + Docker container escape kits + XMRig + credential stealers + Kubernetes exploits.

(4) cluster- defining Tsunami IRC-based DDoS backdoor + Diamorphine Linux kernel module rootkit + XMRig Monero coinminer + Sliver C2 framework multi- malware toolset signature establishing cloud- native-focused malware family.

(5) cluster- defining multi-service credential theft tradecraft signature targeting SSH + AWS + Docker + s3cfg + GitHub + Shodan + gcloud + Ngrok + Pidgin + FileZilla + HexChat + MoneroGuiWallet + CloudFlared + davfs2 + PostgreSQL + smbClients establishing comprehensive cloud + Linux + chat + crypto wallet + database service credential coverage.

(6) cluster-defining German-speaking actor + Dutch language affinity attribution indicators per Aqua Security analyst notes establishing European-language operational signature.

(7) cluster-defining 2024 Chimaera + Docker Gatling Gun campaign resurgence signature with September 2024 solscan.life/ chimaera/sh + October 2024 Docker Gatling Gun campaigns + new solscan.life + solscan.one + solscan.online + solscan.store domains registered September 24 2024 + devnull.anondns.net AnonDNS infrastructure obfuscation.

(8) cluster-defining Docker Swarm enlistment + renting-breached-servers business model evolution per Aqua Security establishing 2024 access-as-a-service business model expansion from pure cryptojacking.

(9) signature pnscan + masscan + zgrab port-22 LAN scanning + spread_ssh.sh propagation script + SSH brute force lateral movement tradecraft; (10) signature anondns devnull.anondns.net anonymous DNS abuse for infrastructure obfuscation pointing to IP 45.154.2.77.

(11) signature MITRE ATT&CK Framework industry-standard cluster designation per Cyjax research legitimizing TeamTNT tracking; cluster fills the TeamTNT-financially-motivated- cybercrime-cloud-native-cryptojacking-specialist + Docker-REST-API-Kubernetes-JupyterLab- misconfiguration-exploitation + Tsunami-Diamorphine- XMRig-Sliver-multi-malware-toolset + DockerHub- alpineos-malicious-container-image-abuse + German-speaking-actor-indicators + 2024-Chimaera- Docker-Gatling-Gun-campaign-resurgence + multi- service-credential-theft-tradecraft + Docker- Swarm-renting-breached-servers-business-model- evolution + 2019-active-since position in v0.1.178 heterogeneous nation-state + criminal cluster gap-filler cell.

canonical illustration of cloud-native cybercrime specialization + Docker/ Kubernetes/JupyterLab misconfiguration exploitation + DockerHub-as-distribution-infrastructure tradecraft + Tsunami/Diamorphine/XMRig/Sliver multi-malware family + multi-service cloud credential theft + German-speaking actor attribution indicators + 2024 Chimaera + Docker Gatling Gun resurgence campaigns + Docker Swarm enlistment renting-breached-servers business model evolution cited in essentially all subsequent cloud-cryptojacking industry analyses through 2019-2026 period.

financially_motivated_cybercrime_cloud_native_cryptojacking_specialist_german_speaking_indicators confidence: high 24 aliases MITRE ATT&CK G0139 ↗
Sigma rules201 YARA rules0 Live IOCs0 CVEs exploited0

Profile

TeamTNT is a financially-motivated cybercrime group specializing in cloud-native environment exploitation for cryptojacking active since at least 2019 with German-speaking actor attribution indicators per Aqua Security analysis, Docker REST API + Kubernetes + JupyterLab misconfiguration exploitation specialization, DockerHub abuse via alpineos account distributing malicious container images, Tsunami backdoor + Diamorphine rootkit + XMRig Monero coinminer + Sliver C2 framework multi-malware toolset, 2024 Chimaera + Docker Gatling Gun campaign resurgence with Docker Swarm enlistment + renting-breached-servers business model evolution. Financially-motivated cybercrime attribution per Aqua Security canonical multi-year tracking + Trend Micro Docker REST API exploitation analysis + Datadog Security Labs 2024 campaign coverage + Cyjax MITRE ATT&CK Framework addition + multi- vendor industry consensus. Honest attribution caveat: 2024 resurgence attribution to TeamTNT is via code similarity + tradecraft pattern (Tsunami malware + dAPIpwn function + German-language C2 server responses); Aqua Security acknowledges possibility of "advanced copycat" emulating TeamTNT code as alternative attribution.

Standalone cluster paralleling unc1860 + unc4990 + confucius in v0.1.178 heterogeneous nation- state + criminal cluster gap-filler cell.

Operational target profile
  • Misconfigured Docker REST API endpoints.
  • Exposed Kubernetes API servers.
  • Misconfigured JupyterLab servers.
  • CentOS VPS instances.
  • Opportunistic global targeting (financially- motivated) Operational attack architecture: (1) Cloud-native cryptojacking specialization (cluster-defining) (2) Docker REST API + Kubernetes + JupyterLab misconfiguration exploitation (cluster-defining) (3) DockerHub alpineos malicious container image abuse (cluster-defining) (4) Tsunami + Diamorphine + XMRig + Sliver multi-malware toolset (cluster-defining) (5) Multi-service credential theft tradecraft (cluster-defining) (6) German-speaking actor indicators (cluster- defining) (7) 2024 Chimaera + Docker Gatling Gun campaign resurgence (cluster-defining) (8) Docker Swarm enlistment + renting-breached- servers business model evolution (cluster- defining) The cluster fills the TeamTNT-financially- motivated-cybercrime-cloud-native-cryptojacking- specialist + Docker-REST-API-Kubernetes-JupyterLab- misconfiguration-exploitation + Tsunami-Diamorphine- XMRig-Sliver-multi-malware-toolset + DockerHub- alpineos-malicious-container-image-abuse + German-speaking-actor-indicators + 2024-Chimaera- Docker-Gatling-Gun-campaign-resurgence + multi- service-credential-theft-tradecraft + Docker- Swarm-renting-breached-servers-business-model- evolution + 2019-active-since position in v0.1.178 heterogeneous nation-state + criminal cluster gap-filler cell.

Aliases

24
teamtntteam tntteam_tnttntcrewtnt crewteamtnt cybercrime groupteamtnt cloud cryptojacking specialistteamtnt docker kubernetes exploitationteamtnt aqua security trend micro trackingteamtnt tsunami backdoor malwareteamtnt diamorphine rootkitteamtnt xmrig monero coinminerteamtnt sliver malware c2 frameworkteamtnt dockerhub alpineos malicious image abuseteamtnt chimaera campaign 2024 septemberteamtnt docker gatling gun campaign 2024 octoberteamtnt german-speaking actor indicatorsteamtnt 2024 cloud-native cryptojacking resurgenceteamtnt ssh brute force lateral movementteamtnt jupyterlab exposed server exploitationteamtnt cloud credential theft aws docker s3 githubteamtnt anondns devnull anondns net infrastructureteamtnt solscan life domain campaign infrastructureteamtnt docker swarm renting breached servers business model

Notable Campaigns

11
2024TeamTNT September 2024 Chimaera Campaign Signature
2024TeamTNT October 2024 Docker Gatling Gun Campaign Signature
2024TeamTNT Docker Swarm Enlistment + Renting Breached Servers Third-Party Business Model Evolution
2021-2024TeamTNT 2021 Apparent Cessation + 2024 Resurgence Signature
2021TeamTNT MITRE ATT&CK Framework Industry-Standard Cluster Designation Addition Signature
2019-2026Continued Industry Reference Status (2019-2026)
2019-2024TeamTNT Tsunami + Diamorphine + XMRig + Sliver Multi-Malware Toolset Signature
2019-2024TeamTNT Multi-Service Credential Theft Tradecraft Signature
2019-2024TeamTNT German-Speaking Actor + Dutch Language Affinity Attribution Indicators
2019-2023TeamTNT DockerHub alpineos Account Malicious Container Image Distribution Signature
2019TeamTNT Origin, 2019 Cloud-Native Cryptojacking Emergence

Attribution & Reporting

Attributed by
Aqua Security (canonical TeamTNT cluster tracking + 2024 Chimaera + Docker Gatling Gun campaign attribution + German-speaking actor indicators)Trend Micro / Nitesh Surana (canonical Docker REST API exploitation analysis + alpineos DockerHub abuse)Datadog Security Labs (canonical 2024 Docker Swarm + Kubernetes cryptojacking campaign tracking low-confidence)Cyjax (canonical TeamTNT MITRE ATT&CK Framework addition)Group-IB (canonical October 2024 observation)Cybersec Sentinel (canonical Docker Security Alert TeamTNT Rootkits Cryptominers coverage)Wiz Cloud Threat Landscape (canonical TeamTNT cloud-fluent threat actor designation)Intezer (canonical 2022 IP attribution 147.75.47.199)The Hacker News (canonical Notorious Hacker Group TeamTNT Launches New Cloud Attacks coverage)Infosecurity Magazine (canonical Experts Warn of Impending TeamTNT Docker Attacks coverage)Dark Reading (canonical TeamTNT Hits Docker Containers via 150K Malicious Cloud Image Pulls coverage)
Key reporting
reportAqua Security: canonical TeamTNT cluster tracking 2019-2024 + Chimaera + Docker Gatling Gun campaign attribution
reportTrend Micro / Nitesh Surana: canonical Docker REST API exploitation analysis + alpineos DockerHub abuse
reportDatadog Security Labs: canonical 2024 Docker Swarm + Kubernetes cryptojacking campaign tracking low-confidence
reportCyjax: canonical TeamTNT MITRE ATT&CK Framework addition
reportGroup-IB: canonical October 2024 observation
reportCybersec Sentinel: Docker Security Alert TeamTNT Rootkits Cryptominers, canonical coverage
reportWiz Cloud Threat Landscape: canonical TeamTNT cloud-fluent threat actor designation
reportThe Hacker News: Notorious Hacker Group TeamTNT Launches New Cloud Attacks for Crypto Mining, canonical coverage
reportInfosecurity Magazine: Experts Warn of Impending TeamTNT Docker Attacks, canonical coverage

Operational

State sponsor

TeamTNT is a financially-motivated cybercrime group specializing in cloud-native environment exploitation for cryptojacking active since at least 2019, with indicators suggesting German- speaking actor attribution per Aqua Security analysis. Per Wiz Cloud Threat Landscape: "TeamTNT is a financially-motivated and highly cloud-fluent threat actor known for exploiting misconfigurations in container management software and Kubernetes clusters to hijack containerized environments and run cryptomining operations." Honest attribution caveat: TeamTNT attribution is based on operational pattern consistency across multi-vendor tracking (Aqua Security + Trend Micro + Datadog + Cyjax) with German- speaking actor indicators (C2 server replies in German, "distinct sense of humor" and "affinity for the Dutch language" per Aqua Security). The group appeared to cease activities in late 2021, but 2024 Chimaera + Docker Gatling Gun campaigns attributed to TeamTNT via Tsunami malware code similarity + dAPIpwn function reuse + C2 server German-language responses.

Aqua Security acknowledges possibility of "advanced copycat" emulating TeamTNT code as alternative attribution. Attribution chain: (1) Aqua Security canonical TeamTNT tracking 2019-2021 + 2024 resurgence: Aqua Security established canonical TeamTNT cluster tracking with multiple campaign disclosures from 2019 through 2021 + 2024 Chimaera + Docker Gatling Gun campaign resurgence canonical attribution. (2) Trend Micro canonical Docker REST API exploitation analysis: per Trend Micro / Nitesh Surana via Dark Reading: TeamTNT analysis from honeypot exposure with Docker Daemon REST API showed German-based IP attribution + DockerHub registry abuse via alpineos + multiple malicious container images including rootkits + Docker container escape kits + XMRig Monero coin miner + credential stealers + Kubernetes exploits. (3) Datadog Security Labs September 2024 campaign tracking with low-confidence TeamTNT attribution: per Datadog Security Labs: cryptojacking campaign leveraging Docker Swarm + Kubernetes for cryptocurrency mining at scale with TeamTNT attribution based on Intezer 2022 IP attribution (147.75.47.199) + spread_ssh.sh + pnscan scanning tradecraft + Kubernetes lateral movement; attribution assigned low-confidence due to lack of corroborating evidence. (4) MITRE ATT&CK Framework TeamTNT designation: TeamTNT added to MITRE ATT&CK Framework per Cyjax research establishing industry-standard cluster designation. (5) 2024 Chimaera + Docker Gatling Gun campaign canonical resurgence: per Aqua Security + The Hacker News + Infosecurity Magazine + Cybersec Sentinel: "TeamTNT appears to be readying for a new large-scale campaign targeting cloud-native environments for mining cryptocurrencies and renting out breached servers to third-parties" with Sliver malware + Docker Swarm enlistment + DockerHub infrastructure + solscan.life domain campaign + devnull.anondns.net anonymous DNS abuse. (6) German-speaking actor indicators per Aqua Security: "Aqua Security linked the new campaign to the group via the Tsunami malware it commonly used, use of the dAPIpwn function and a C2 server that replies in German" + "distinct sense of humor" and "affinity for the Dutch language" per Infosecurity Magazine via Aqua. Cluster-defining German-speaking actor attribution indicator + possible advanced-copycat caveat. (7) Multi-platform credentials theft signature: per Aqua Security: TeamTNT targets credentials of SSH + AWS + Docker + s3cfg + GitHub + Shodan + gcloud + Ngrok + Pidgin + FileZilla + HexChat + MoneroGuiWallet + CloudFlared + davfs2 + PostgreSQL + smbClients establishing cluster- defining multi-service credential theft tradecraft.

Operational target profile
  • Misconfigured Docker REST API endpoints signature primary infection vector.
  • Exposed Kubernetes API servers signature.
  • Misconfigured JupyterLab servers signature.
  • CentOS VPS instances signature.
  • Cloud-native infrastructure broad targeting.
  • AWS + GCP + Azure cloud credential targets signature.
  • DockerHub free Container Registry abuse signature.
  • No specific industry/geography targeting per opportunistic financially-motivated model The cluster fills the TeamTNT-financially- motivated-cybercrime-cloud-native-cryptojacking- specialist + Docker-REST-API-Kubernetes-JupyterLab- misconfiguration-exploitation + Tsunami-Diamorphine- XMRig-Sliver-multi-malware-toolset + DockerHub- alpineos-malicious-container-image-abuse + German-speaking-actor-indicators + 2024-Chimaera- Docker-Gatling-Gun-campaign-resurgence + multi- service-credential-theft-tradecraft + Docker- Swarm-renting-breached-servers-business-model- evolution + 2019-active-since position in v0.1.178 heterogeneous nation-state + criminal cluster gap-filler cell.
Motivations
financially_motivated_cybercrime_cloud_native_cryptojacking_specialist, docker_kubernetes_jupyterlab_misconfiguration_exploitation_signature, tsunami_diamorphine_xmrig_sliver_multi_malware_toolset, dockerhub_alpineos_malicious_container_image_abuse_signature, german_speaking_actor_attribution_indicators, 2024_chimaera_docker_gatling_gun_campaign_resurgence_signature, cloud_credentials_theft_multi_service_tradecraft_signature, docker_swarm_renting_breached_servers_business_model_evolution
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)55/60 · 91%
Analytics (MITRE CAR)27/60 · 45%
Runtime / container (Falco)9/60 · 15%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)19/60 · 31%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MULTI-SERVICE CREDENTIAL THEFT TRADECRAFT (AWS + DOCKER + S3CFG + GITHUB + SHODAN + GCLOUD + NGROK + PIDGIN + FILEZILLA + HEXCHAT + MONEROGUIWALLET + CLOUDFLARED + DAVFS2 + POSTGRESQL + SMBCLIENTS)SLIVER MALWARE C2 FRAMEWORK 2024 RESURGENCE SIGNATURESLIVER MALWARESOLSCAN.LIFE SOLSCAN.ONE SOLSCAN.ONLINE SOLSCAN.STORE 2024 CAMPAIGN INFRASTRUCTURESPREAD SSH.SH PROPAGATION SCRIPT SIGNATURESSH BRUTE FORCE LATERAL MOVEMENT TRADECRAFT
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin