logo

TeamTNT is Back and Attacking Vulnerable Redis Servers

ID: 6799eaa9-4d18-5311-a964-a881012418bc

STIX ID: report--6799eaa9-4d18-5311-a964-a881012418bc

Feed Name: Aqua Security Blog

Threat Score
75/100

Date Published: 2020-09-30

Date Updated: 2026-04-26

...
...

TeamTNT has been publishing malicious container images on Docker Hub (account 'kirito666') which search for misconfigured Docker APIs and vulnerable Redis services to push a two-stage attack: initial compromise via Redis exploits and subsequent payload retrieval from S3/IPLogger C2s. Payloads include cryptominers, Tsunami/Rekoobee backdoors, DDoS tools (bioset), and credential-stealing tools (MimiPenguin) to harvest Linux desktop passwords and SSH credentials; the report provides attack flow analysis, MITRE ATT&CK mappings, and a comprehensive list of IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.