TeamTNT, a Famous Hacker Collective, Initiates Fresh Assaults on Cloud Services for Cryptocurrency Mining.

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Cloud Security Threat: TeamTNT Targeting Cloud Environments for Crypto Mining

TeamTNT, the notorious cryptojacking group, is gearing up for a new large-scale campaign targeting cloud-native environments for mining cryptocurrencies and renting out breached servers to third-parties. Assaf Morag, director of threat intelligence at Aqua, reported that the group is currently targeting exposed Docker daemons to deploy Sliver malware and cryptominers, using compromised servers and Docker Hub as infrastructure to spread their malware.

TeamTNT has been observed not only offering victims’ computational power for illicit cryptocurrency mining but also diversifying its monetization strategy. The attack campaign emerged earlier this month when Datadog disclosed malicious attempts to corral infected Docker instances into a Docker Swarm, hinting at TeamTNT’s involvement.

The attacks involve identifying unauthenticated and exposed Docker API endpoints, deploying cryptominers, and selling compromised infrastructure to others on a mining rental platform called Mining Rig Rentals. The group is also using open-source Sliver command-and-control (C2) framework for remotely commandeering infected servers.

Trend Micro recently highlighted a new campaign involving a targeted brute-force attack against a customer to deliver the Prometei crypto mining botnet. The botnet spreads by exploiting vulnerabilities in Remote Desktop Protocol (RDP) and Server Message Block (SMB) to mine cryptocurrencies like Monero on compromised machines without the victim’s knowledge.

These developments underscore the evolving tactics of threat actors in the cryptocurrency space and the increasing sophistication of their attacks. The cybersecurity community is on high alert as groups like TeamTNT continue to adapt and expand their operations.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Citrix NetScaler ADC and Gateway Products Face Critical Vulnerabilities CVE-2026-19489 and CVE-2026-19490

Australian organisations using Citrix NetScaler ADC and Citrix NetScaler Gateway products should be aware of critical vulnerabilities identified by Citrix. These vulnerabilities, CVE-2026-19489 and...

Police Warn of Rising Cyber Extortion Scams Involving Intimate Images and Video Calls

SINGAPORE – The police have issued a warning regarding a surge in cyber extortion scams that involve intimate images and sexually explicit video calls....

US Senator Requests NSA Guidance on Best Practices for VPN Use Against Foreign Surveillance

A prominent US senator is urging the National Security Agency (NSA) to provide public guidance on best practices for using virtual private networks (VPNs)...

Cisco Patches Critical Nexus 9000 Vulnerability Allowing Remote Code Execution as Root

Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker...