TeamTNT Taps Docker to Unleash Sliver Malware in Major Cloud Assault

Amber | Attack Report

TeamTNT, a notorious hacking group, is preparing a large-scale campaign targeting cloud-native environments, marking a return to their original methods. The group is leveraging exposed Docker daemons as a critical entry point, allowing them to infiltrate and exploit vulnerable cloud infrastructures. Through these entry points, TeamTNT aims to deploy the Sliver malware, and a cyber worm alongside cryptominers, using compromised servers and Docker Hub as pillars of their malicious ecosystem. This approach highlights the group’s adaptability and emphasizes the critical need for vigilant cloud security to thwart resource hijacking and malware spread.

Reduce real exposure. Not just vulnerability volume.