logo

An analysis of a TeamTNT doppelgänger

ID: 33035e63-90b9-5cd1-8304-05219f9ea1cc

STIX ID: report--33035e63-90b9-5cd1-8304-05219f9ea1cc

Feed Name: Datadog Security Labs

Threat Score
78/100

Date Published: 2024-02-01

Date Updated: 2026-04-27

...
...

This report describes an active opportunistic campaign (observed Nov 2023–Jan 2024) scanning Internet-facing Docker APIs to compromise misconfigured hosts, install backdoors and remote-access tools, steal cloud credentials (AWS/Azure/GCP), create persistent IAM admin users, and deploy XMRig miners while using Linux userland anti-forensics to hide activity; researchers identified hundreds of infected machines, leaked credential lists, C2 infrastructure, and several IOCs (IPs, script hashes, service names, SSH key fingerprints).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.