TeamTNT
TeamTNT is a threat actor focused on cloud and containerized environments. The provided content describes activity including searching for unsecured AWS credentials and Docker API credentials; scanning for open Docker API ports, Kubernetes clusters, vulnerable cloud services, and IoT devices; and using masscan as well as malware leveraging zmap and zgrab to identify exposed services. TeamTNT has aggregated collected credentials into text files before exfiltration and used curl to send credentials over HTTP, while using curl and wget to download additional software. The actor has deployed batch scripts to download tools, execute cryptocurrency miners, and establish persistence by adding batch scripts to the Startup folder. TeamTNT has executed PowerShell commands in batch scripts. The content also states that TeamTNT replaced .dockerd and .dockerenv with its own scripts and cryptocurrency mining software. For reconnaissance and evasion, TeamTNT has searched for system version, architecture, and hostname information; searched for attached VGA devices using lspci; searched for rival malware and removed it if found; and searched for running processes containing the strings aliyun or liyun to identify machines running Alibaba Cloud Security tools. TeamTNT disabled and uninstalled security tools such as Alibaba, Tencent, and BMC cloud monitoring agents on cloud-based infrastructure. The actor has used payloads that remove themselves after running and deleted locally staged files used for credential collection or local IP scan results after exfiltration. The content also notes use of AES encryption for binaries, Base64-encoded files, and a script that decodes a Base64-encoded version of WeaveWorks Scope. Aliases mentioned in the content: teamtnt.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
Associated vulnerabilities
8 CVEs this actor has used in observed campaigns. 8 of them exploited in the wild.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
The following analytic detects attempts to exploit CVE-2022-26134, an unauthenticated remote code execution vulnerability in Confluence... This activity is significant as it allows attackers to execute arbitrary code on the Confluence server without authentication, potentially leading to full system compromise.
3 more CVEs tied to this actor tracked in Mallory.
Observables
97 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named threat actor referenced in Linux cloud threat reporting.
Associated with the cgroup/service name pattern sad_service.service as a known-malicious indicator for Linux-focused detection.
Targets Linux cloud and container environments, abusing legitimate Linux and cloud administration tools, cron jobs, SSH persistence, exposed Docker APIs, weak cloud configurations, and mounted host filesystems to deploy cryptominers and move laterally.
Listed as a threat actor associated with the PowerShell P/Invoke process injection API chain detection and related ATT&CK techniques.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.