TeamTNT is Back and Attacking Vulnerable Redis Servers
ID: 6799eaa9-4d18-5311-a964-a881012418bc
STIX ID: report--6799eaa9-4d18-5311-a964-a881012418bc
Feed Name: Aqua Security Blog
TeamTNT has been publishing malicious container images on Docker Hub (account 'kirito666') which search for misconfigured Docker APIs and vulnerable Redis services to push a two-stage attack: initial compromise via Redis exploits and subsequent payload retrieval from S3/IPLogger C2s. Payloads include cryptominers, Tsunami/Rekoobee backdoors, DDoS tools (bioset), and credential-stealing tools (MimiPenguin) to harvest Linux desktop passwords and SSH credentials; the report provides attack flow analysis, MITRE ATT&CK mappings, and a comprehensive list of IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
