TeamTNT Reemerged with New Aggressive Cloud Campaign
ID: be83784b-4338-5fd6-84e3-6271d2bc3668
STIX ID: report--be83784b-4338-5fd6-84e3-6271d2bc3668
Feed Name: Aqua Security Blog
Aqua Nautilus analyzed a TeamTNT campaign (aka Silentbob) that operates a high-speed Internet-wide scanner and worm targeting cloud-native infrastructure (exposed Docker APIs, Kubernetes, Jupyter, Weave Scope, Redis, Hadoop, SSH, etc.). The actors deploy Tsunami-based botnet binaries, credential-stealing scripts (AWS/Azure/GCP), backdoors (SSH keys, Gsocket, tmate, ngrok), persistence (runc disable, restart containers), rootkit-based process hiding, and publicly hosted malicious Docker images; researchers obtained the C2, observed active IRC C2 channels and hundreds of infected hosts, and captured numerous IOCs (IP 45.9.148.108, AnonDNS subdomains, file names and MD5 hashes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
