Black-T is a TeamTNT cryptojacking malware variant targeting Linux-based cloud environments, particularly systems exposing Docker daemon APIs. It combines opportunistic cloud compromise, worm-like propagation, credential collection, and Monero mining. Black-T follows TeamTNT’s established tradecraft of abusing exposed container infrastructure, but adds more aggressive post-compromise actions including removal of rival miners, broader scanning activity, and theft of cloud-relevant credentials and secrets.
On compromised hosts, Black-T performs environment preparation and cleanup, including terminating competing cryptojacking malware and related processes, adjusting system settings, and installing dependencies needed for propagation and mining. It deploys multiple scanning tools to identify additional targets, including scanners for exposed Docker services and broader network reconnaissance beyond local address space. Reported variants also scan for additional ports associated with follow-on exploitation opportunities.
Black-T includes credential-access functionality aimed at cloud and administrator material. It has been observed collecting shell histories, SSH material, cron data, Docker-related files, and AWS credential and configuration data. It also uses Linux memory password-scraping tools to recover credentials from process memory, marking a notable expansion beyond pure mining activity into credential theft. Stolen data is archived and exfiltrated to attacker-controlled infrastructure.
For monetization, Black-T deploys cryptocurrency-mining payloads for Linux and configures them for Monero mining. It is associated with TeamTNT, a cloud-focused intrusion set known for exploiting exposed Docker services and misconfigured cloud infrastructure. Later Black-T samples were also observed wrapped with the Ezuri Linux crypter/loader, indicating an effort to improve defense evasion through in-memory execution and reduced on-disk visibility.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Later variants of TeamTnT's malware, such as "Black-T" that install network scanners on infected systems and extract AWS credentials from memory were also found to be laced with Ezuri.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
"memory password scraping operations via mimipy and mimipenguins"; "Upon uncovering any passwords residing in memory... written to ... output.txt"
51 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A TeamTNT cryptojacking variant referenced for comparison, noted for Kubernetes and Docker API targeting patterns absent from the newer WatchDog scripts.
Referenced only in a citation title as a cryptojacking variant from TeamTNT.
A TeamTnT malware variant that installs network scanners on infected systems and extracts AWS credentials from memory; the article says variants were packed with Ezuri.
Mentioned only as related background content on cryptojacking, with no substantive discussion in the article body.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.