216.73.216.6

A Deep Dive into TeamTNT and Spinning YARN

· Published 18/12/2024 06:34 · Modified 18/12/2024 12:09

Export JSON

Essential information

Published
18/12/2024 06:34
Modified
18/12/2024 12:09
Tags
2024-12-18 cloud security confluence crypto mining docker linux obfuscation platypus redis spinning yarn xmrig yarn
Related entities
35 observables, 1 intrusion sets (apt), 21 techniques (mitre), 2 malware, 1 others

Description

TeamTNT is conducting a campaign called , targeting , , , and . The attack involves server-side scripting vulnerabilities, obfuscated code, and malware deployment. The malware assesses the environment, disables , establishes persistence, and sets up a crypto miner. The impact extends beyond resource consumption, granting the attacker persistent access for potential further exploitation. TeamTNT, active since 2019, is known for attacks on cloud environments and cryptojacking. The campaign utilizes various tools and tactics, including malware droppers, miners, and reverse shells. Organizations should prioritize securing their infrastructure and stay informed about evolving threats to and cloud environments.

External references