logo

TeamTNT Reemerged with New Aggressive Cloud Campaign

ID: be83784b-4338-5fd6-84e3-6271d2bc3668

STIX ID: report--be83784b-4338-5fd6-84e3-6271d2bc3668

Feed Name: Aqua Security Blog

Threat Score
78/100

Date Published: 2023-07-13

Date Updated: 2026-04-26

...
...

Aqua Nautilus analyzed a TeamTNT campaign (aka Silentbob) that operates a high-speed Internet-wide scanner and worm targeting cloud-native infrastructure (exposed Docker APIs, Kubernetes, Jupyter, Weave Scope, Redis, Hadoop, SSH, etc.). The actors deploy Tsunami-based botnet binaries, credential-stealing scripts (AWS/Azure/GCP), backdoors (SSH keys, Gsocket, tmate, ngrok), persistence (runc disable, restart containers), rootkit-based process hiding, and publicly hosted malicious Docker images; researchers obtained the C2, observed active IRC C2 channels and hundreds of infected hosts, and captured numerous IOCs (IP 45.9.148.108, AnonDNS subdomains, file names and MD5 hashes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.