Uptime Hamster: 10d 12h 14mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza TeamTNT

TeamTNT

1 incidentes 1 paises 0 sectores apt DE Ultimo: 2026-05-25
Aliases: Adept Libra
Ver en IntelTracker → APTTrail →
TeamTNT is a financially motivated cybercrime group, primarily identified in late 2019, specializing in cryptojacking attacks against cloud and containerized environments. The group is notably characterized by its German-speaking members and a unique public persona, often interacting with cybersecurity researchers on social media platforms. TeamTNT's primary motivation is financial gain, achieved through the illicit mining of cryptocurrencies like Monero using compromised compute resources and the theft of cloud credentials, particularly AWS keys, to expand their operations. They distinguish themselves by focusing specifically on cloud-native environments, being recognized as the first crypto-mining worm to actively steal AWS credentials, and for abusing legitimate tools to establish persistence. After a period of reduced activity in 2022, the group re-emerged in 2023 with refined tactics.

Aliases del actor

Adept Libra

Actores similares

Silent Librarianactor · 1returned-libraactor · 1silent-librarianactor · 1Returned Libraapt · 0Librarian Ghoulsapt · 0
Tecnicas MITRE
T1595.002, T1114.001, T1547.001, T1111, T1553, T1112
CVEs relacionadas
CVE-2023-38831, CVE-2023-36884, CVE-2022-47966, CVE-2022-42889, CVE-2022-42475, CVE-2022-41352
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Sectores objetivo (SOCRadar)

Energy & Utilities Information ServicesData Processing ServicesConstructionSoftware PublishersWired and Wireless Telecommunications CarriersComputer Systems Design and Related ServicesComputer Systems Design Services