Security researchers have warned that the infamous TeamTNT group may be gearing up for another major campaign against cloud-native environments after discovering attackers targeting misconfigured servers.
Aqua Security launched an investigation after detecting an attack against one of its honeypots. Later, four malicious containers of her image were discovered. However, given that some of the code functions remain unused and appear to have undergone some manual testing, the researchers theorize that the campaign has not yet fully launched. added.
“This infrastructure is in the early stages of testing and deployment and is primarily consistent with aggressive cloud worms, and has been used to deploy Tsunami malware, cloud credential hijacking, resource hijacking, and further worm intrusions. , is designed to deploy to the public JupyterLab and Docker APIs.”
“We strongly believe TeamTNT is behind this new campaign.”
Read more about TeamTNT: TeamTNT attack highlights the need for cloud governance
TeamTNT is a prolific cybercriminal group known for its aggressive attacks on cloud-based systems, especially Docker and Kubernetes environments. It specializes in cryptomining, but has evolved over time to include other malicious activities.
While TeamTNT appeared to be dormant in late 2021, Aqua Security managed to launch a new campaign via the commonly used Tsunami malware, the use of dAPIpwn functionality, and C2 servers responding in German. associated with the group.
The researchers haven’t ruled out the possibility of a “sophisticated imitator”, but one that could emulate TeamTNT’s code, with a “peculiar sense of humor” and an “affinity for the Dutch language”. would need to be a highly sophisticated group.
New threat activity uncovered by Aqua Security shows attackers identifying misconfigured Docker API or JupyterLab servers and deploying containers or manipulating the command line interface (CLI) to scan for additional victims It starts when you specify
“This process is designed to spread the malware to more servers,” the blog post states. “The secondary payload of this attack includes a cryptominer and a backdoor, the latter weaponized by the Tsunami malware.”
Aqua Security posted a list of recommendations to help organizations mitigate threats.