TeamTNT, a Famous Hacker Collective, Initiates Fresh Assaults on Cloud Services for Cryptocurrency Mining.

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Cloud Security Threat: TeamTNT Targeting Cloud Environments for Crypto Mining

TeamTNT, the notorious cryptojacking group, is gearing up for a new large-scale campaign targeting cloud-native environments for mining cryptocurrencies and renting out breached servers to third-parties. Assaf Morag, director of threat intelligence at Aqua, reported that the group is currently targeting exposed Docker daemons to deploy Sliver malware and cryptominers, using compromised servers and Docker Hub as infrastructure to spread their malware.

TeamTNT has been observed not only offering victims’ computational power for illicit cryptocurrency mining but also diversifying its monetization strategy. The attack campaign emerged earlier this month when Datadog disclosed malicious attempts to corral infected Docker instances into a Docker Swarm, hinting at TeamTNT’s involvement.

The attacks involve identifying unauthenticated and exposed Docker API endpoints, deploying cryptominers, and selling compromised infrastructure to others on a mining rental platform called Mining Rig Rentals. The group is also using open-source Sliver command-and-control (C2) framework for remotely commandeering infected servers.

Trend Micro recently highlighted a new campaign involving a targeted brute-force attack against a customer to deliver the Prometei crypto mining botnet. The botnet spreads by exploiting vulnerabilities in Remote Desktop Protocol (RDP) and Server Message Block (SMB) to mine cryptocurrencies like Monero on compromised machines without the victim’s knowledge.

These developments underscore the evolving tactics of threat actors in the cryptocurrency space and the increasing sophistication of their attacks. The cybersecurity community is on high alert as groups like TeamTNT continue to adapt and expand their operations.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

European Parliament Calls for Delay in Serbia’s EU Accession Over Spyware Concerns

A group of European Parliament representatives is advocating for a delay in Serbia's entry into the European Union due to concerns over the government's...

Estate Planning in the UAE Embraces Digital Transformation, Says Blanket Founder

UAE Estate Planning Enters Digital Transformation Era The UAE is witnessing a significant shift in estate planning as the traditionally complex process begins to embrace...

Edge AI Shifts Security Responsibilities to Customers in New Trust Model

Edge AI shifts the responsibility of security from centralized cloud providers to customers, fundamentally altering the trust model for AI systems. Edge AI refers to...

UK Account-Hack Losses Increase 417% Amid New Reporting System Implementation

Reported losses associated with hacked email, social media, and other online accounts in the UK surged by 417% over the last financial year, reaching...