FORENSIA

THREAT_ACTOR · G0139

TeamTNT

Also known as: TeamTNT

Profile

TeamTNT is a threat group that has primarily targeted cloud and containerized environments. The group as been active since at least October 2019 and has mainly focused its efforts on leveraging cloud and container resources to deploy cryptocurrency miners in victim environments.

MITRE ATT&CK ↗

Techniques

56 ATT&CK techniques attributed to this actor.

T1007 System Service DiscoveryT1014 RootkitT1016 System Network Configuration DiscoveryT1021.004 SSHT1027.002 Software PackingT1027.013 Encrypted/Encoded FileT1036 MasqueradingT1036.005 Match Legitimate Resource Name or LocationT1046 Network Service DiscoveryT1048 Exfiltration Over Alternative ProtocolT1049 System Network Connections DiscoveryT1057 Process DiscoveryT1059.001 PowerShellT1059.003 Windows Command ShellT1059.004 Unix ShellT1059.009 Cloud APIT1059.013 Container CLI/APIT1070.003 Clear Command HistoryT1070.004 File DeletionT1071 Application Layer ProtocolT1071.001 Web ProtocolsT1074.001 Local Data StagingT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1098.004 SSH Authorized KeysT1102 Web ServiceT1105 Ingress Tool TransferT1120 Peripheral Device DiscoveryT1133 External Remote ServicesT1136.001 Local AccountT1140 Deobfuscate/Decode Files or InformationT1204.003 Malicious ImageT1219 Remote Access ToolsT1222.002 Linux and Mac PermissionsT1496.001 Compute HijackingT1518.001 Security Software DiscoveryT1543.002 Systemd ServiceT1543.003 Windows ServiceT1547.001 Registry Run Keys / Startup FolderT1552.001 Credentials In FilesT1552.004 Private KeysT1552.005 Cloud Instance Metadata APIT1569.003 SystemctlT1583.001 DomainsT1587.001 MalwareT1595.001 Scanning IP BlocksT1595.002 Vulnerability ScanningT1608.001 Upload MalwareT1609 Container Administration CommandT1610 Deploy ContainerT1611 Escape to HostT1613 Container and Resource DiscoveryT1680 Local Storage DiscoveryT1685 Disable or Modify ToolsT1685.006 Clear Linux or Mac System LogsT1686 Disable or Modify System Firewall

Software

4 malware/tools attributed to this actor.

MimiPenguinLaZagneHildegardPeirates

Related corpus activity

10,441 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to TeamTNT.

IndicatorTypeFamilySevSrc
cve-2023-44976cveransomware852
cve-2026-1969cve851
cve-2025-68670cve852
cve-2026-3102cve853
cve-2025-2492cve852
cve-2021-29441cve851
cve-2026-22584cve852
cve-2025-11837cve852
cve-2025-34054cve854
cve-2014-2321cve851
cve-2020-17456cve851
cve-2020-22658cve852
cve-2017-18377cve851
cve-2021-25646cve851
cve-2025-66478cve852
cve-2025-0921cve852
cve-2021-27076cve851
cve-2013-3307cve852
cve-2016-5681cve852
cve-2016-15047cve854
cve-2024-1781cve851
cve-2018-8007cve851
cve-2025-23304cve852
cve-2021-4045cve851
cve-2020-22653cve852
cve-2022-47945cve851
cve-2025-34117cve851
cve-2026-4368cveransomware851
cve-2013-7471cve851
cve-2026-0740cve851

Showing the top 30 by severity of 10,441.