TeamTNT is a financially motivated cloud-focused threat actor best known for opportunistic cryptojacking and credential-harvesting operations targeting exposed and misconfigured cloud infrastructure, especially Docker, Kubernetes, and related Linux-based environments. The group has repeatedly targeted internet-accessible container services and cloud workloads, using shell scripts, container images, and lightweight malware to gain execution, deploy cryptocurrency miners, establish persistence, and steal credentials—particularly cloud credentials such as AWS-related secrets. TeamTNT is widely associated with attacks against exposed Docker daemons, containerized workloads, and unauthenticated or weakly secured cloud services. The actor has also been observed uploading backdoored container images to public registries to facilitate downstream compromise. Reported campaigns include the cloud-focused operation referred to as Silent Bob, which involved scanning for exposed services, propagating across additional servers, deploying a miner, installing a Tsunami backdoor, and harvesting cloud credentials. The group’s tradecraft is heavily Linux- and cloud-centric and commonly relies on command and scripting interpreters, especially shell scripts, along with standard administrative utilities such as curl, wget, lspci, and other native tools. Observed behaviors include discovery of system version, architecture, hostname, disk and logical volume information, host IP address enumeration, peripheral discovery, and checks for installed security products. TeamTNT has also searched process environments for cloud-related variables and credentials, including AWS-associated environment data. Credential access and collection are central to TeamTNT operations. The actor has been observed harvesting credentials from files and environment variables and exfiltrating them over HTTP. In cloud intrusions, this credential theft supports both monetization and lateral expansion across additional workloads and accounts. Persistence and execution techniques attributed to TeamTNT include adding startup scripts, installing miners as services, and using encoded or obfuscated payload components. The group has also used malware and scripts that download additional tooling, decode embedded content, and maintain access through backdoors in addition to cryptomining payloads. TeamTNT is generally tracked as a cybercriminal rather than nation-state actor. Attribution of individual script-based incidents can be difficult because TeamTNT tooling is often simple, modular, and easily copied, but the group remains one of the most recognizable names associated with cloud-native cryptojacking and credential theft. Known aliases in the provided reporting consist of TeamTNT.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
57 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
8 CVEs this actor has used in observed campaigns. 8 of them exploited in the wild.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
The following analytic detects attempts to exploit CVE-2022-26134, an unauthenticated remote code execution vulnerability in Confluence... This activity is significant as it allows attackers to execute arbitrary code on the Confluence server without authentication, potentially leading to full system compromise.
3 more CVEs tied to this actor tracked in Mallory.
125 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an example threat actor associated with deploying known cryptominer binaries on Linux systems.
Listed in annotations associated with the credential-access technique.
Mentioned as a commodity-focused cryptomining threat actor used as a comparison point for wallet reuse behavior.
Listed in the detection annotations as a threat actor associated with this analytic context.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.