TeamTNT (Cloud Cryptojacking Operator)
TeamTNT is a financially-motivated cybercrime group specializing in cloud-native environment exploitation for cryptojacking active since at least 2019 with German-speaking actor attribution indicators per Aqua Security analysis ("Aqua Security linked the new campaign to the group via the Tsunami malware it commonly used, use of the dAPIpwn function and a C2 server that replies in German") + Docker REST API + Kubernetes + JupyterLab misconfiguration exploitation specialization + DockerHub abuse via alpineos account distributing malicious container images + Tsunami IRC-based DDoS backdoor + Diamorphine Linux kernel module rootkit + XMRig Monero coinminer + Sliver C2 framework multi-malware toolset + 2024 Chimaera (September) + Docker Gatling Gun (October) campaign resurgence with Docker Swarm enlistment + renting-breached- servers-to-third-parties business model evolution; financially-motivated cybercrime attribution per Aqua Security canonical multi-year tracking + Trend Micro / Nitesh Surana canonical Docker REST API exploitation analysis ("The threat actors found the misconfiguration and exploited it thrice from IPs based in Germany, where they were logged in to their DockerHub registry... the motivation of the attacker was to exploit the Docker REST API and compromise the underlying server to perform cryptojacking") + Datadog Security Labs 2024 Docker Swarm + Kubernetes cryptojacking campaign tracking + Cyjax MITRE ATT&CK Framework addition + Group-IB October 2024 observation + Wiz Cloud Threat Landscape canonical cloud-fluent threat actor designation + Cybersec Sentinel + The Hacker News + Infosecurity Magazine multi-vendor industry consensus.
honest attribution caveat 2024 resurgence attribution to TeamTNT is via code similarity + tradecraft pattern (Tsunami malware + dAPIpwn function + German-language C2 server responses)
Aqua Security acknowledges possibility of "advanced copycat" emulating TeamTNT code as alternative attribution ("similar to a similarly sophisticated group capable of emulating TeamTNT code and which has a 'distinct sense of humor' and 'affinity for the Dutch language'")
standalone cluster paralleling unc1860 + unc4990 + confucius in v0.1.178 heterogeneous nation-state + criminal cluster gap-filler cell.
operational target profile signature misconfigured Docker REST API endpoints + exposed Kubernetes API servers + misconfigured JupyterLab servers + CentOS VPS instances + opportunistic global targeting (financially-motivated no industry/geography focus)
operational attack architecture: (1) cluster-defining cloud-native cryptojacking specialization with Docker + Kubernetes + cloud-native infrastructure focus distinguishing from traditional enterprise-focused cybercrime actors.
(2) cluster-defining Docker REST API + Kubernetes + JupyterLab misconfiguration exploitation signature with exposed API endpoints as primary infection vectors.
(3) cluster-defining DockerHub alpineos account malicious container image distribution tradecraft abusing DockerHub free Container Registry services to distribute payloads including coin miners + rootkits + Docker container escape kits + XMRig + credential stealers + Kubernetes exploits.
(4) cluster- defining Tsunami IRC-based DDoS backdoor + Diamorphine Linux kernel module rootkit + XMRig Monero coinminer + Sliver C2 framework multi- malware toolset signature establishing cloud- native-focused malware family.
(5) cluster- defining multi-service credential theft tradecraft signature targeting SSH + AWS + Docker + s3cfg + GitHub + Shodan + gcloud + Ngrok + Pidgin + FileZilla + HexChat + MoneroGuiWallet + CloudFlared + davfs2 + PostgreSQL + smbClients establishing comprehensive cloud + Linux + chat + crypto wallet + database service credential coverage.
(6) cluster-defining German-speaking actor + Dutch language affinity attribution indicators per Aqua Security analyst notes establishing European-language operational signature.
(7) cluster-defining 2024 Chimaera + Docker Gatling Gun campaign resurgence signature with September 2024 solscan.life/ chimaera/sh + October 2024 Docker Gatling Gun campaigns + new solscan.life + solscan.one + solscan.online + solscan.store domains registered September 24 2024 + devnull.anondns.net AnonDNS infrastructure obfuscation.
(8) cluster-defining Docker Swarm enlistment + renting-breached-servers business model evolution per Aqua Security establishing 2024 access-as-a-service business model expansion from pure cryptojacking.
(9) signature pnscan + masscan + zgrab port-22 LAN scanning + spread_ssh.sh propagation script + SSH brute force lateral movement tradecraft; (10) signature anondns devnull.anondns.net anonymous DNS abuse for infrastructure obfuscation pointing to IP 45.154.2.77.
(11) signature MITRE ATT&CK Framework industry-standard cluster designation per Cyjax research legitimizing TeamTNT tracking; cluster fills the TeamTNT-financially-motivated- cybercrime-cloud-native-cryptojacking-specialist + Docker-REST-API-Kubernetes-JupyterLab- misconfiguration-exploitation + Tsunami-Diamorphine- XMRig-Sliver-multi-malware-toolset + DockerHub- alpineos-malicious-container-image-abuse + German-speaking-actor-indicators + 2024-Chimaera- Docker-Gatling-Gun-campaign-resurgence + multi- service-credential-theft-tradecraft + Docker- Swarm-renting-breached-servers-business-model- evolution + 2019-active-since position in v0.1.178 heterogeneous nation-state + criminal cluster gap-filler cell.
canonical illustration of cloud-native cybercrime specialization + Docker/ Kubernetes/JupyterLab misconfiguration exploitation + DockerHub-as-distribution-infrastructure tradecraft + Tsunami/Diamorphine/XMRig/Sliver multi-malware family + multi-service cloud credential theft + German-speaking actor attribution indicators + 2024 Chimaera + Docker Gatling Gun resurgence campaigns + Docker Swarm enlistment renting-breached-servers business model evolution cited in essentially all subsequent cloud-cryptojacking industry analyses through 2019-2026 period.