TeamTNT’s Docker Gatling Gun Campaign
ID: 3dd94c79-9bef-51ca-9b08-cdd215dccf72
STIX ID: report--3dd94c79-9bef-51ca-9b08-cdd215dccf72
Feed Name: Aqua Security Blog
Threat Score
TeamTNT is preparing a large-scale cloud-focused campaign that exploits exposed Docker daemons (ports like `2375`) and compromised Docker Hub accounts to deploy Sliver implants, worms, and cryptominers; they append victims to Docker Swarms, rent or monetize compute, and maintain C2 infrastructure (domains/IPs listed) while using new tooling (Sliver) alongside legacy capabilities (Tsunami), with multiple IoCs and MITRE ATT&CK mappings provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
