[Guest Diary] A Deep Dive into TeamTNT and Spinning YARN, (Wed, Dec 18th)
ID: 54860d60-e6de-5585-b8a8-973a6eba0afb
STIX ID: report--54860d60-e6de-5585-b8a8-973a6eba0afb
Feed Name: SANS ISC Diary
Threat Score
This report analyzes TeamTNT’s "Spinning YARN" campaign that exploits server-side injection and misconfigured services to deliver Linux-focused malware and an XMRig miner; it documents dropper scripts (w.sh, ar.sh), multiple payload binaries (fkoths, bioset, sshd), IoCs (domains, URLs, IPs, and file hashes), and attacker tactics including disabling cloud security, establishing reverse shells, persistence, and potential AWS credential theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
