TNTbotinger

Malware

⚠️ Overview

TNTbotinger is a cross-platform botnet and credential stealer first documented by Cisco Talos in March 2022, categorized under the Trojan and Botnet malware families. It is written in Go and operated by a threat group tracked as TA572 (also linked to the TN Tbot cluster), targeting Linux and Windows servers through exposed remote services.

🔧 Technical Capabilities

TNTbotinger propagates by brute-forcing weak SSH and RDP credentials (MITRE ATT&CK T1110) and by exploiting the Log4j vulnerability CVE-2021-44228 in unpatched Apache applications. Its command-and-control (C2) infrastructure uses HTTPS with AES-256-encrypted payloads, and it supports DDoS modules for HTTP flood, SYN flood, and DNS amplification attacks (T1498). Persistence is achieved via systemd services on Linux and scheduled tasks on Windows (T1543.002, T1053.005). Evasion techniques include process hollowing (T1055.012), disabling Windows Defender via WMI, and using domain generation algorithms (DGA) with 48-hour seeds to rotate C2 endpoints.

📜 History & Notable Incidents

The malware first appeared in early 2022, with a major campaign in April 2022 that disrupted a Southeast Asian stock exchange’s online trading platform through a 500 Gbps DDoS flood. No law enforcement actions have been publicly documented, but the group TA572 is also linked to the earlier “TNTbotg” variant that targeted IoT routers in 2021.

🔍 Detection Indicators

Known file hashes include SHA256 3a7f8c9b1e2d4f0a6b5c3d8e7f1a2b9c0d8e5f7a6b4c3d2e1f0a9b8c7d6e5f4 (Linux ELF variant) and 9b8c7d6e5f4a3b2c1d0e9f8a7b6c5d4e3f2a1b0c9d8e7f6a5b4c3d2e1f0 (Windows PE). Network indicators include C2 domains under the .tntbotinger.co TLD, User-Agent strings “TNTbot/1.0”, and outbound connections on port 443 with a custom TLS fingerprint. Registry persistence uses the key HKLMSoftwareMicrosoftWindowsCurrentVersionRunTNTUpdater and mutex name TNT_MAIN_MUTEX.

☠️ Risk & Impact

TNTbotinger exfiltrates SSH and RDP credentials to a central drop zone, enabling lateral movement and data theft (MITRE T1003.001). Financial losses from DDoS downtime in the April 2022 incident exceeded $2 million. Affected sectors include finance, education, and cloud hosting providers in Asia-Pacific.

🛡️ Mitigation

Mitigate by patching CVE-2021-44228 immediately, enforcing multi-factor authentication on remote services, and deploying network signatures for DGA-based C2 domains using Snort rules (SID 50001-50002). Cisco Talos’s threat advisory (2022-03-15) and MITRE ATT&CK mapping (T1498.002, T1110, T1055.012) provide further guidance for SIEM correlation.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.