Palo Alto Networks Unit 42 reported that the WatchDog cryptojacking group, not TeamTNT, was responsible for a cloud-focused intrusion campaign that deliberately imitated TeamTNT tradecraft. Investigators said the operation reused TeamTNT-style infrastructure naming, referenced repositories and domains previously linked to TeamTNT, and relied on the known WatchDog command-and-control host 199.19.226.117 alongside WatchDog-associated Monero wallets and mining pools to deploy illicit cryptocurrency miners.
The findings revise an earlier attribution and indicate that WatchDog expanded its cloud operations while attempting to obscure responsibility by blending in with a better-known threat actor. Unit 42 said the campaign did not match TeamTNT’s more recent behavior, noting the absence of its newer Kubernetes and Docker targeting, credential theft activity, and zgrab usage; it also lacked some of WatchDog’s more advanced Go-based tooling, suggesting a hybrid operation built to look like TeamTNT while retaining identifiable WatchDog infrastructure.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
Two malware samples that Unit 42 later tied to WatchDog while imitating TeamTNT tradecraft were first observed on Dec. 5, 2020 and Dec. 11, 2020. The samples used WatchDog-associated infrastructure, wallets, and mining pools while borrowing TeamTNT naming and repository patterns.
Unit 42 reported that new evidence showed a previously reported cloud-focused cryptojacking campaign was conducted by WatchDog rather than TeamTNT. Researchers said WatchDog expanded its operations while deliberately disguising activity to resemble TeamTNT.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 96 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.