TeamTNT abused an exposed Docker API to deploy a privileged Ubuntu container, mount the host filesystem, run cryptominers, and create a privileged SSH user. The group installed the legitimate Weave Scope Docker/Kubernetes administration tool, exposing its web dashboard on default port 4040 to map container environments and execute commands—effectively obtaining backdoor-like control through trusted software rather than custom malware.
A compromised container can also become a path to cloud-account takeover through instance metadata services, pod IAM/AAD identities, embedded long-term cloud keys, and container escapes. Organizations should restrict Docker APIs and Weave Scope access, prevent pod access to metadata endpoints, enforce least-privilege workload identities and Kubernetes RBAC, eliminate long-term credentials from pods and secrets, remediate vulnerable workloads, and segment networks to limit lateral movement.

Map this exposure pattern across your cloud, code, and identities.
2 events from the most recent confirmed update back to the earliest known activity.
Wiz research found that about 40% of surveyed managed-Kubernetes cloud environments had a pod containing a cleartext long-term cloud key, while about 10% had a publicly exposed vulnerable pod associated with a highly privileged IAM or AAD identity. The analysis detailed how compromised pods and nodes can abuse instance metadata, workload identities, secrets, and pod escapes for lateral movement into cloud environments.
Intezer observed TeamTNT exploiting an exposed Docker API to create a privileged Ubuntu container, mount the host filesystem, run cryptominers, and attempt persistence through a privileged SSH user named "hilde." The attackers installed the legitimate Weave Scope tool and used its port-4040 dashboard to map Docker environments and execute commands without a conventional malware backdoor.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.