About this actor
In early Febuary, 2021 TeamTNT launched a new campaign against Docker and Kubernetes environments. Using a collection of container images that are hosted in Docker Hub, the attackers are targeting misconfigured docker daemons, Kubeflow dashboards, and Weave Scope, exploiting these environments in order to steal cloud credentials, open backdoors, mine cryptocurrency, and launch a worm that is looking for the next victim. They're linked to the First Crypto-Mining Worm to Steal AWS Credentials and Hildegard Cryptojacking malware. TeamTNT is a relatively recent addition to a growing number of threats targeting the cloud. While they employ some of the same tactics as similar groups, TeamTNT stands out with their social media presence and penchant for self-promotion. Tweets from the TeamTNT’s account are in both English and German although it is unknown if they are located in Germany.
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Palo Alto Unit 42constellation names
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 75 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
- 2019 — 1 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2019-5736 | 8.7 | 8.6 | 0.9857 | 2019-02-11 | see CVE |
T1007System Service Discovery ↗T1014Rootkit ↗T1016System Network Configuration Discovery ↗T1021Remote Services ↗T1021.004SSH ↗T1027Obfuscated Files or Information ↗T1027.002Software Packing ↗T1027.013Encrypted/Encoded File ↗T1036Masquerading ↗T1036.005Match Legitimate Resource Name or Location ↗T1046Network Service Discovery ↗T1048Exfiltration Over Alternative Protocol ↗T1049System Network Connections Discovery ↗T1057Process Discovery ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.003Windows Command Shell ↗T1059.004Unix Shell ↗T1059.009Cloud API ↗T1059.013Container CLI/API ↗T1070Indicator Removal ↗T1070.003Clear Command History ↗T1070.004File Deletion ↗T1071Application Layer Protocol ↗T1071.001Web Protocols ↗T1074Data Staged ↗T1074.001Local Data Staging ↗T1082System Information Discovery ↗T1083File and Directory Discovery ↗T1098Account Manipulation ↗T1098.004SSH Authorized Keys ↗T1102Web Service ↗T1105Ingress Tool Transfer ↗T1120Peripheral Device Discovery ↗T1133External Remote Services ↗T1136Create Account ↗T1136.001Local Account ↗T1140Deobfuscate/Decode Files or Information ↗T1204User Execution ↗T1204.003Malicious Image ↗T1219Remote Access Tools ↗T1222File and Directory Permissions Modification ↗T1222.002Linux and Mac Permissions ↗T1496Resource Hijacking ↗T1496.001Compute Hijacking ↗T1518Software Discovery ↗T1518.001Security Software Discovery ↗T1543Create or Modify System Process ↗T1543.002Systemd Service ↗T1543.003Windows Service ↗T1547Boot or Logon Autostart Execution ↗T1547.001Registry Run Keys / Startup Folder ↗T1552Unsecured Credentials ↗T1552.001Credentials In Files ↗T1552.004Private Keys ↗T1552.005Cloud Instance Metadata API ↗T1569System Services ↗T1569.003Systemctl ↗T1583Acquire Infrastructure ↗T1583.001Domains ↗T1587Develop Capabilities ↗T1587.001Malware ↗T1595Active Scanning ↗T1595.001Scanning IP Blocks ↗T1595.002Vulnerability Scanning ↗T1608Stage Capabilities ↗T1608.001Upload Malware ↗T1609Container Administration Command ↗T1610Deploy Container ↗T1611Escape to Host ↗T1613Container and Resource Discovery ↗T1680Local Storage Discovery ↗T1685Disable or Modify Tools ↗T1685.006Clear Linux or Mac System Logs ↗T1686Disable or Modify System Firewall ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 42 / 75 | 56% |
CM-6 | 41 / 75 | 55% |
AC-3 | 34 / 75 | 45% |
AC-6 | 32 / 75 | 43% |
CM-2 | 32 / 75 | 43% |
AC-2 | 31 / 75 | 41% |
CM-7 | 29 / 75 | 39% |
SI-3 | 28 / 75 | 37% |
SI-7 | 28 / 75 | 37% |
CA-7 | 26 / 75 | 35% |
IA-2 | 24 / 75 | 32% |
AC-5 | 23 / 75 | 31% |
SC-7 | 20 / 75 | 27% |
CM-5 | 18 / 75 | 24% |
AC-17 | 17 / 75 | 23% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- Rocke 0.37
- OilRig 0.26
- Operation Wocao 0.25
- BlackByte 0.25
- Tropic Trooper 0.25
Active in same years
- Lazarus Group 1.00
- Tonto Team 1.00
- Andariel 1.00
- BlackByte 1.00
- Storm-0530 1.00