An analysis of a TeamTNT doppelgänger
ID: 33035e63-90b9-5cd1-8304-05219f9ea1cc
STIX ID: report--33035e63-90b9-5cd1-8304-05219f9ea1cc
Feed Name: Datadog Security Labs
This report describes an active opportunistic campaign (observed Nov 2023–Jan 2024) scanning Internet-facing Docker APIs to compromise misconfigured hosts, install backdoors and remote-access tools, steal cloud credentials (AWS/Azure/GCP), create persistent IAM admin users, and deploy XMRig miners while using Linux userland anti-forensics to hide activity; researchers identified hundreds of infected machines, leaked credential lists, C2 infrastructure, and several IOCs (IPs, script hashes, service names, SSH key fingerprints).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
