Tracking the Activities of TeamTNT: A Closer Look at a Cloud-Focused Malicious Actor Group
ID: 110ad5f7-4edb-4246-8403-accb9652f601
STIX ID: report--110ad5f7-4edb-4246-8403-accb9652f601
Threat Score
75/100
Uploaded: 2026-08-19
Published Date: 2021-07-15
Last Modified Date: 2021-07-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro's research tracks the activities of the cloud-focused threat actor TeamTNT, outlining its campaigns Covid-19, Black-T, Kinsing Killer, Docker4Mac and AWS credential theft, among others, the range of payloads including cryptocurrency miners, credential stealers, IRC bots, backdoors and the Diamorphine rootkit, and its evolution toward targeting cloud infrastructure and services with credential harvesting and container-focused attacks, accompanied by mitigation recommendations.
