TeamTNT is a financially motivated cybercrime group active since at least 2020 that primarily targets exposed and misconfigured cloud-native infrastructure, especially Docker environments, Kubernetes deployments, and related APIs. The group is best known for opportunistic compromise of Linux and containerized environments to deploy cryptocurrency miners, repurpose victim infrastructure for botnet activity, and harvest cloud credentials. TeamTNT commonly abuses exposed container services and weakly secured cloud workloads for initial access. Post-compromise activity includes downloading additional tooling, executing shell and PowerShell commands, using batch scripts, collecting host and network configuration details, enumerating running processes, identifying security products, and removing competing malware from infected systems. The group has also searched for cloud- and container-related secrets, including unsecured AWS credentials, Docker API credentials, SSH keys, and Kubernetes service tokens. TeamTNT has used HTTP-based communications for payload retrieval and credential transmission, and has acquired domains to host payloads. The group demonstrates defense-evasion and persistence tradecraft, including self-deleting payloads, checks for cloud security tooling such as Alibaba Cloud security products, and use of startup-folder persistence on Windows systems. TeamTNT has also developed custom malware, notably Hildegard, and later variants such as Black-T have been associated with credential extraction from memory and deployment of network scanners. TeamTNT malware has been observed packed with Ezuri, a Linux in-memory loader and crypter used to reduce antivirus detection. TeamTNT is widely tracked under the single name TeamTNT.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
50 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
35 malware families attributed to this actor across reporting.
30 additional families tracked in Mallory.
8 CVEs this actor has used in observed campaigns. 8 of them exploited in the wild.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
The following analytic detects attempts to exploit CVE-2022-26134, an unauthenticated remote code execution vulnerability in Confluence... This activity is significant as it allows attackers to execute arbitrary code on the Confluence server without authentication, potentially leading to full system compromise.
3 more CVEs tied to this actor tracked in Mallory.
588 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting attacks against cloud and container environments, including Kubernetes and Docker, to steal AWS credentials and enable lateral movement; previously associated with cryptocurrency mining and credential theft.
Mentioned only as a referenced cryptojacking crew in related/background context; the article itself focuses on an unnamed Monero mining campaign on Linux servers, not on TeamTNT activity.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Referenced as an example threat actor associated with deploying known cryptominer binaries on Linux systems.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.