logo

TeamTNT__2020__TeamTNT_activity_targets_Weave_Scope_deployments_-_Microsoft_Tech_Community_-_1645968.pdf

ID: 52e5164e-1db7-4298-a8e8-94956524f34e

STIX ID: report--52e5164e-1db7-4298-a8e8-94956524f34e

Threat Score

78/100

Uploaded: 2026-08-19

Published Date: 2020-09-09

Last Modified Date: 2020-09-09

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
The report details TeamTNT’s campaign that targets exposed Docker and Kubernetes management interfaces, deploying a mining payload via the hildeteamtnt/pause-amd64:3.4 image, using scanning and auto-spawning techniques to propagate across clusters, and exposing Weave Scope as a key access vector, alongside indicators and security recommendations.