logo

Tracking the Activities of TeamTNT: A Closer Look at a Cloud-Focused Malicious Actor Group

ID: 110ad5f7-4edb-4246-8403-accb9652f601

STIX ID: report--110ad5f7-4edb-4246-8403-accb9652f601

Threat Score

75/100

Uploaded: 2026-08-19

Published Date: 2021-07-15

Last Modified Date: 2021-07-15

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro's research tracks the activities of the cloud-focused threat actor TeamTNT, outlining its campaigns Covid-19, Black-T, Kinsing Killer, Docker4Mac and AWS credential theft, among others, the range of payloads including cryptocurrency miners, credential stealers, IRC bots, backdoors and the Diamorphine rootkit, and its evolution toward targeting cloud infrastructure and services with credential harvesting and container-focused attacks, accompanied by mitigation recommendations.