Threat Alert: New Malware in the Cloud By TeamTNT
ID: db52a6f4-0fd3-5aa4-814c-279d62029f26
STIX ID: report--db52a6f4-0fd3-5aa4-814c-279d62029f26
Feed Name: Aqua Security Blog
This report analyzes three recent honeypot-detected campaigns attributed to TeamTNT that exploit misconfigured Docker and Redis services to deploy cryptominers, rootkits (Diamorphine, prochider), credential theft tooling, and container-escape techniques; it also documents a novel distributed Pollard’s Kangaroo ECDLP solver used to attempt breaking SECP256K1 keys. The authors provide script-level breakdowns (k.sh, cronb.sh, dc.sh, en.sh, b.sh, c.sh), C2 infrastructure (93.95.229.203, 205.185.118.246, domain whatwill.be), and a Tsunami malware MD5, assessing that TeamTNT may be resuming active operations against cloud-native environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
