TeamTNT
1 incidentes
1 paises
0 sectores
apt DE Ultimo: 2026-05-25
Aliases: Adept Libra
TeamTNT is a financially motivated cybercrime group, primarily identified in late 2019, specializing in cryptojacking attacks against cloud and containerized environments. The group is notably characterized by its German-speaking members and a unique public persona, often interacting with cybersecurity researchers on social media platforms. TeamTNT's primary motivation is financial gain, achieved through the illicit mining of cryptocurrencies like Monero using compromised compute resources and the theft of cloud credentials, particularly AWS keys, to expand their operations. They distinguish themselves by focusing specifically on cloud-native environments, being recognized as the first crypto-mining worm to actively steal AWS credentials, and for abusing legitimate tools to establish persistence. After a period of reduced activity in 2022, the group re-emerged in 2023 with refined tactics.
Sectores objetivo (SOCRadar)
Energy & Utilities Information ServicesData Processing ServicesConstructionSoftware PublishersWired and Wireless Telecommunications CarriersComputer Systems Design and Related ServicesComputer Systems Design Services