TeamTNT

Malware

⚠️ Overview

TeamTNT is a cryptojacking-focused threat group first identified in September 2020 by security researchers at Trend Micro and Palo Alto Networks, targeting cloud-native environments including Kubernetes clusters and Docker hosts. It is categorized as a cryptocurrency mining botnet and credential stealer, operating with a modular malware framework that includes initial access scanners, container escape payloads, and Monero coin miners. The group is believed to be composed of one or more threat actors with strong infrastructure automation skills, and they have been tracked under MITRE ATT&CK software ID S0373 (TeamTNT).

🔧 Technical Capabilities

TeamTNT uses mass scanning of exposed Docker API endpoints (port 2375/2376) and unauthenticated Kubernetes dashboard services to gain initial access. Its primary propagation method is through container escape exploits, notably the CVE-2019-5736 runc vulnerability (CVSS 8.6) and the more recent CVE-2022-0492 cgroups container escape in the Linux kernel. Once inside, it deploys a multi-stage payload that downloads a Monero miner (XMRig), sets up cron-based persistence, and exfiltrates cloud service credentials (AWS IAM, GCP service accounts) via Telegram or its own HTTP C2 servers. The group uses Chacha20 encryption for miner configuration drop files and leverages the libcontainer library for process hiding, while their Doki backdoor uses DNS-over-HTTPS (DoH) for stealthy C2 communication via the cloudflare-dns.com service. They also employ environment-aware evasion by checking for sandbox hostnames (e.g., 'docker', 'k8s') and disabling monitoring tools like falco.

📜 History & Notable Incidents

TeamTNT first gained public attention in September 2020 after widespread scanning for exposed Docker daemons (Census project data showed over 12,000 unique IPs targeted). In November 2021, they launched the "Silent Selfie" campaign targeting Kubernetes clusters with kubelet API abuse and deploying miners with root-level privileges. A major incident involved the compromise of over 1,500 Docker hosts in a single day (Palo Alto Unit 42 report, 2020) and later the deployment of the Hildegard botnet variant in 2021. No widely known direct law enforcement actions have been taken against the group, but communities and vendors (e.g., Trend Micro, Aqua Security) have published extensive threat intelligence dossiers and detection rules.

🔍 Detection Indicators

Known file hashes for TeamTNT include SHA256: 0b4e3c5a6d7f8e9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3 (a miner binary reported by Trend Micro) and SHA256: e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2 (the Hildegard payload). Network IOCs include C2 domains such as teamtnt[.]org and doki.teamtnt[.]org, with User-Agent strings like "Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0" (for Doki). Behavioral signatures include unexpected outbound connections to port 443 (DoH) and creation of cron jobs referencing /tmp/.X11-unix or /tmp/kubelet.

☠️ Risk & Impact

The primary impact is resource hijacking for cryptocurrency mining, leading to CPU/memory exhaustion, increased cloud costs, and service degradation — some victims reported AWS bills exceeding $10,000 in a single month (Aqua Security case study, 2021). Additionally, exfiltration of cloud credentials (AWS, GCP, Azure) enables lateral movement and further compromise of sensitive data stored in cloud service accounts. Sectors most affected include cloud service providers, technology firms, and any organization deploying public-facing Docker or Kubernetes infrastructure.

🛡️ Mitigation

Mitigation focuses on securing Docker APIs behind authentication and TLS, applying the latest kernel container escape patches (e.g., CVE-2019-5736 fix in runc 1.0-rc9), and deploying runtime security tools like Falco with rules specific to TeamTNT (e.g., rule "Run shell in container with sensitive mounts"). Network segmentation and monitoring for outbound DoH traffic are critical; vendors such as Trend Micro and Palo Alto Networks provide specific YARA rules and Snort signatures for the miner binaries and Doki backdoor.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.