THREAT_ACTOR · G0139
TeamTNT
Also known as: TeamTNT
Profile
TeamTNT is a threat group that has primarily targeted cloud and containerized environments. The group as been active since at least October 2019 and has mainly focused its efforts on leveraging cloud and container resources to deploy cryptocurrency miners in victim environments.
MITRE ATT&CK ↗Techniques
56 ATT&CK techniques attributed to this actor.
T1007 System Service DiscoveryT1014 RootkitT1016 System Network Configuration DiscoveryT1021.004 SSHT1027.002 Software PackingT1027.013 Encrypted/Encoded FileT1036 MasqueradingT1036.005 Match Legitimate Resource Name or LocationT1046 Network Service DiscoveryT1048 Exfiltration Over Alternative ProtocolT1049 System Network Connections DiscoveryT1057 Process DiscoveryT1059.001 PowerShellT1059.003 Windows Command ShellT1059.004 Unix ShellT1059.009 Cloud APIT1059.013 Container CLI/APIT1070.003 Clear Command HistoryT1070.004 File DeletionT1071 Application Layer ProtocolT1071.001 Web ProtocolsT1074.001 Local Data StagingT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1098.004 SSH Authorized KeysT1102 Web ServiceT1105 Ingress Tool TransferT1120 Peripheral Device DiscoveryT1133 External Remote ServicesT1136.001 Local AccountT1140 Deobfuscate/Decode Files or InformationT1204.003 Malicious ImageT1219 Remote Access ToolsT1222.002 Linux and Mac PermissionsT1496.001 Compute HijackingT1518.001 Security Software DiscoveryT1543.002 Systemd ServiceT1543.003 Windows ServiceT1547.001 Registry Run Keys / Startup FolderT1552.001 Credentials In FilesT1552.004 Private KeysT1552.005 Cloud Instance Metadata APIT1569.003 SystemctlT1583.001 DomainsT1587.001 MalwareT1595.001 Scanning IP BlocksT1595.002 Vulnerability ScanningT1608.001 Upload MalwareT1609 Container Administration CommandT1610 Deploy ContainerT1611 Escape to HostT1613 Container and Resource DiscoveryT1680 Local Storage DiscoveryT1685 Disable or Modify ToolsT1685.006 Clear Linux or Mac System LogsT1686 Disable or Modify System Firewall
Software
4 malware/tools attributed to this actor.
MimiPenguinLaZagneHildegardPeirates
Related corpus activity
10,441 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to TeamTNT.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2014-2321 | cve | — | 85 | 1 |
| cve-2020-17456 | cve | — | 85 | 1 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2017-18377 | cve | — | 85 | 1 |
| cve-2021-25646 | cve | — | 85 | 1 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2021-4045 | cve | — | 85 | 1 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2025-34117 | cve | — | 85 | 1 |
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2013-7471 | cve | — | 85 | 1 |
| cve-2026-0740 | cve | — | 85 | 1 |
Showing the top 30 by severity of 10,441.