s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.teamtnt

📛 Threat Title

Malware family: TeamTNT

Category: TeamTNT First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.teamtnt`. Printable name: TeamTNT.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.teamtnt VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.teamtnt

IOC database

Type
domain
Value
elf.teamtnt
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.teamtnt

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.teamtnt

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    TeamTNT's campaign initiates with SSH brute force attacks, allowing the attacker to upload malicious scripts that disable critical security features, delete logs, and manipulate system files. The script actively searches for existing cryptocurrency miners, terminating any found processes and removing associated Docker containers.

  • web:attack.mitre.org

    TeamTNT is a threat group that has primarily targeted cloud and containerized environments. The group as been active since at least October 2019 and has mainly focused its efforts on leveraging cloud and container resources to deploy cryptocurrency miners in victim environments.

  • web:cybersecsentinel.com

    TeamTNT has renewed its focus on targeting Docker and Kubernetes environments in cloud-based infrastructures. Their tactics involve exploiting exposed Docker APIs, deploying rootkits, and using malware that includes the Tsunami backdoor and customized cryptomining scripts to establish persistent control, hijack resources, and escalate ...

  • web:documents.trendmicro.com

    Indeed, TeamTNT launched a number of campaigns in 2020 and early 2021. Some of them were fairly simple and straightforward, such as the group's Covid-19 campaign, which capitalized on pandemic-related topics for its malware nomenclature. Others made full use of the TeamTNT's repertoire of tools and techniques.

  • web:hivepro.com

    Targeted Region: Worldwide Attack: TeamTNT is a notorious cybercriminal group, active since 2019, known for targeting cloud and container environments worldwide to deploy cryptocurrency miners. Although they appeared to disband in November 2021 after announcing their exit on Twitter, TeamTNT re-emerged with new cyber campaigns, evolving their capabilities and focusing on Virtual Private Server ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Since Fall 2019, Team TNT is a well known threat actor which targets *nix based systems and misconfigured Docker container environments. It has constantly evolved its capabilities for its cloud-based cryptojacking operations. They have shifted their focus on compromising Kubernetes Clusters.

  • web:sos-vo.org

    TeamTNT carried out numerous cryptojacking attacks, using victims' Information Technology (IT) resources to mine cryptocurrency illegally. According to Group-IB, the threat actor emerged in 2019 with its "homebrewed" malware involving an advanced toolkit of shell scripts and malicious binaries.

  • web:thehackernews.com

    The infamous cryptojacking group known as TeamTNT appears to be readying for a new large-scale campaign targeting cloud-native environments for mining cryptocurrencies and renting out breached servers to third-parties. "The group is currently targeting exposed Docker daemons to deploy Sliver malware ...

  • web:www.group-ib.com

    Team TNT targets cloud systems through cryptojacking and SSH brute-force attacks, causing over $430,000 in damages across Europe and APAC.

  • web:www.infosecurity-magazine.com

    TeamTNT was a prolific threat actor known for cryptojacking attacks, which use victims' IT resources to illegally mine for cryptocurrency. The likely German-speaking actor first emerged in 2019 and became infamous for its "homebrewed malware using a comprehensive toolkit of shell scripts and malicious binaries," according to Group-IB.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.