TeamTNT continued to evolve from a Linux-focused cryptojacking group into a broad cloud threat actor targeting exposed Redis, Docker, Kubernetes, Jupyter, Hadoop, PostgreSQL, Tomcat, Nginx, SSH, and other internet-facing services. Researchers tied the group to worm-like campaigns that rapidly scanned for vulnerable hosts, deployed XMRig miners, dropped Tsunami-based IRC bots including DDoS-capable variants, and used malicious container images on Docker Hub to spread payloads at scale. One TeamTNT-linked Docker Hub account reportedly served images pulled more than 150,000 times, while later campaigns showed the group abusing public registries, compromised accounts, and cloud-native tooling to infect newly exposed systems and report them back to command-and-control infrastructure.
Across these operations, TeamTNT consistently paired monetization with aggressive credential theft and stealth. Investigations found the group harvesting AWS, Azure, GCP, Kubernetes, Git, NPM, Grafana, database, and storage secrets; stealing SSH keys and host data; and using tools such as Weave Scope, Peirates, BotB, MimiPenguin, Mimipy, tmate, and Gsocket to expand access and persistence. Analysts also documented detection evasion through log wiping, process hiding, LD_PRELOAD userland rootkits, the Diamorphine kernel rootkit, privileged containers with restart policies, and even disabling runc to lock out rival attackers, underscoring TeamTNT’s shift from opportunistic mining to sustained compromise of cloud and container environments.

Pull IOCs and campaign context straight into your stack.
20 events from the most recent confirmed update back to the earliest known activity.
Group-IB reported a cloud-focused intrusion campaign attributed with moderate confidence to TeamTNT targeting CentOS-based VPS infrastructure via SSH brute-force attacks. After access, the attackers deployed a shell script that disabled defenses, removed logs, killed competing miners, established persistence with cron jobs and SSH backdoors, created a sudo-capable user named hilde, changed SSH to port 11222, and deployed the Diamorphine rootkit alongside a custom tool called tntrecht.
On 2022-09-15, Aqua disclosed three newly observed honeypot attacks it linked to TeamTNT, indicating the group had resumed active operations after roughly eleven months without new campaigns. The Kangaroo, Cronb, and 'What Will Be' attacks targeted misconfigured Docker environments and reused classic TeamTNT techniques while adding new infrastructure and, in one case, distributed Pollard’s Kangaroo SECP256K1 key-solving activity.
Virus Bulletin reported that TeamTNT compromised insecure Kubernetes kubelets and pods, then installed legitimate NVIDIA GPU drivers and XMRig to boost cryptomining on victim cloud workloads. The report also described scripts that queried Google Cloud metadata, selected OS-specific driver packages for Debian and Ubuntu, and fetched payloads from attacker-controlled infrastructure.
On 2021-12-01, Trend Micro reported that TeamTNT used compromised Docker Hub accounts to deploy privileged containers, abuse Weave Scope Cloud for remote control of compromised environments, and escape to hosts with bind mounts and nsenter. The report also described a separate workflow using masscan and zgrab to enumerate exposed kubelet APIs on TCP port 10250, indicating preparation for further Kubernetes targeting.
On 2021-09-30, Uptycs reported a TeamTNT-linked malicious Docker Hub image named "Dockerapi" hosted under the alpineos account to Docker Hub's security team. The image used an embedded script to scan victim subnets for additional Docker targets and deploy follow-on payloads including XMRig, Tsunami, and a Diamorphine rootkit.
Samples observed in August and September 2021 showed TeamTNT developing more modular, Kubernetes-specific payloads, improving targeting of AWS and Kubernetes environments, and rotating command-and-control infrastructure. The report also said the group expanded cryptomining operations to GPU-equipped systems to improve Monero mining returns.
Trend Micro observed TeamTNT using the DockerHub account alpineos in exploitation attempts against exposed Docker REST API honeypots from mid-September to early October 2021. The account hosted malicious images containing rootkits, Docker escape kits, XMRig miners, credential stealers, Kinsing, and Kubernetes exploit kits.
In July 2021, Trend Micro published earlier research on TeamTNT infiltration via the Docker API and identified 26 DockerHub accounts assessed as compromised or malicious. This documented the group's broader abuse of container registries for malware delivery.
On 2021-05-18, Trend Micro reported that TeamTNT had significantly expanded its post-compromise credential harvesting to target a wider range of cloud and non-cloud services, including SSH and SMB credentials. The malware used harvested credentials for worm-like lateral movement, automated access via a .netrc file, and exfiltration of collected configuration data to a command-and-control server.
Between March and May 2021, TeamTNT conducted a worm-like campaign abusing exposed or weakly secured kubelet APIs to compromise nearly 50,000 IPs across Kubernetes clusters. Trend Micro said the attackers used the kube.lateral.sh script to scan via port 10250, enumerate pods, execute commands in containers, and deploy XMRig-based Monero mining payloads.
Akamai reported that on 2021-03-04 it observed in honeypot logs a Golang-based Monero miner that exploited a ThinkPHP vulnerability to fetch a loader script and install a UPX-packed binary named sysrvv. The malware established cron persistence, killed competing miners, weakened host defenses, and included code for WordPress and JupyterLab credential attacks and exploitation.
Palo Alto Networks attributed the custom malware Cetus to TeamTNT in August 2020. This marked a public attribution of another malware component to the group.
In February 2020, TeamTNT used the domain teamtnt.red in attacks against unprotected Redis servers. The campaign abused Redis FLUSHALL to create cron jobs that downloaded the group's setup script and installed additional malware.
Toward the end of 2020, TeamTNT began the Docker4Mac campaign targeting Docker users on macOS with a trojanized Weave Scope-derived script. The malware stole cloud service provider credentials and deployed a cryptocurrency miner in the same routine.
In summer 2020, TeamTNT broadened its credential theft to include AWS credentials from ~/.aws/credentials and ~/.aws/config. During the same period it also used the Diamorphine Linux rootkit to conceal miner processes.
In spring 2020, TeamTNT shifted to exploiting exposed Docker daemon ports to deploy cryptominers and DDoS malware. The infections used containers with the host root filesystem mounted so commands executed in the container could modify the host as root.
Intezer assesses TeamTNT has been active since at least October 2019, initially compromising exposed Redis servers. Early campaigns used shell scripts, Tsunami IRC bot malware, and Rathole while spreading to additional Redis hosts.
Sysdig disclosed a TeamTNT attack against a misconfigured WordPress pod in a Kubernetes cluster, where attackers brute-forced access through an exposed Kubernetes dashboard, achieved remote command execution, and downloaded a bash script named aws2.sh. The script attempted to steal AWS credentials from environment variables, running containers, local credential files, and the EC2 instance metadata service, then exfiltrated the collected data to an attacker-controlled server at 84.201.153.234.
Aqua Nautilus accessed a TeamTNT command-and-control server and documented a broad cloud-focused botnet campaign targeting Docker, Kubernetes, Jupyter, Weave Scope, Redis, Hadoop, Postgres, Tomcat, Nginx, and SSH-exposed systems. The operation used credential theft, backdoors, cryptominers, rootkits, and malicious Docker Hub images while continuously scanning for new victims.
Researchers later found TeamTNT leaking credentials from at least two attacker-controlled DockerHub accounts, alpineos and sandeep078, through Docker registry authentication behavior. They reported both accounts to Docker after observing their use in malicious image deployment.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 313 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
26 references tracked. Mallory keeps watching after this page renders.
sysdig.com
Open sourceattack.mitre.org
Open sourceintezer.com
Open sourceintezer.com
Open sourcecadosecurity.com
Open sourcecadosecurity.com
Open sourcedocuments.trendmicro.com
Open sourceweave.works
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.