TeamTNT is a Linux-focused cybercrime threat cluster best known for cloud and container intrusions that monetize access through unauthorized Monero mining and broad credential theft. The group has repeatedly targeted exposed or weakly secured cloud-native infrastructure, including Docker environments and misconfigured container services, and has also exploited weak operational security such as exposed private keys, reused passwords, and cloud misconfigurations to gain access.
Its tooling and tradecraft center on Linux and containerized environments. TeamTNT has used malicious containers and abused exposed Docker REST APIs to deploy payloads, launch privileged containers, mount host filesystems, and pivot from containers to underlying hosts. Operations have included internet-scale scanning for additional exposed Docker services and enumeration of Kubernetes-related services, enabling worm-like propagation across cloud estates and adjacent systems.
A defining characteristic of TeamTNT activity is aggressive credential harvesting after compromise. The malware has searched compromised systems and connected environments for cloud and non-cloud service configuration files, application data, and stored credentials, including SSH and SMB credentials. It has also targeted Docker registry credentials and used harvested access to move laterally, automate logins, and potentially enable follow-on abuse such as cloud resource hijacking or supply-chain compromise. Collected data is exfiltrated to attacker-controlled infrastructure.
TeamTNT commonly relies on native Linux utilities and lightweight shell-based tooling for execution, discovery, persistence, and evasion. Observed behaviors include use of common command-line tools to download and execute payloads, inspect users and processes, alter cron-based persistence, clear shell history, and remove competing miners or traces of activity. The group has also used SSH-based propagation and techniques that facilitate container escape and host-level post-exploitation.
Although TeamTNT is frequently associated with cryptojacking, its operations extend beyond simple miner deployment. Campaigns have incorporated host reconnaissance, credential access, lateral movement, persistence, exfiltration, and post-compromise abuse of legitimate administration and monitoring technologies in container environments. TeamTNT is widely tracked as a significant Linux and cloud threat actor whose activity illustrates the convergence of cryptomining, credential theft, and cloud-native intrusion tradecraft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In early November, we disclosed that compromised Docker Hub accounts were being used for cryptocurrency mining and that these activities were tied to the TeamTNT threat actor.
In early November, we disclosed that compromised Docker Hub accounts were being used for cryptocurrency mining and that these activities were tied to the TeamTNT threat actor.
In early November, we disclosed that compromised Docker Hub accounts were being used for cryptocurrency mining and that these activities were tied to the TeamTNT threat actor.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In the group’s latest attack routine, we found new evidence that TeamTNT has further extended its credential harvesting capabilities to target multiple cloud and non-cloud services in victims’ internal networks and systems post-compromise.
1 distinct technique documented for this family, organized by ATT&CK tactic.
128 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a known Linux-focused cryptomining threat used as an example of malware that signature-based detection can efficiently identify.
Annotations ID Technique Tactic T1048 Exfiltration Over Alternative Protocol Exfiltration TeamTNT
Named threat activity referenced in connection with abuse of Linux utilities such as chattr; not the main malware subject of this article.
Cloud-focused malware/toolset associated with illicit cryptocurrency mining, abuse of exposed Docker/Kubernetes environments, container escape techniques, credential theft from Docker config files, and reconnaissance of exposed kubelets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.