Analysis of TeamTNT Technique Using Container Images to Attack
ID: dbfb0ca6-776d-5f1f-8aad-62eaf55b6986
STIX ID: report--dbfb0ca6-776d-5f1f-8aad-62eaf55b6986
Feed Name: Aqua Security Blog
Team Nautilus analyzed the Docker Hub account hildeteamtnt tied to TeamTNT and found eight malicious container images used to deploy cryptominers, Docker escape binaries, backdoors, and bind shells; dynamic sandbox execution revealed scripts and binaries that kill competing miners, mount/chroot host filesystems, establish SSH persistence, disable security tools, and conceal activity. The report includes detailed IOCs (domains, IP addresses, MD5 hashes), documents evolving evasive techniques across image versions, and maps the campaign behaviors to the MITRE ATT&CK framework.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
