TeamTNT Taps Docker to Unleash Sliver Malware in Major Cloud Assault

Amber | Attack Report
Download PDF

TeamTNT, a notorious hacking group, is preparing a large-scale campaign targeting cloud-native environments, marking a return to their original methods. The group is leveraging exposed Docker daemons as a critical entry point, allowing them to infiltrate and exploit vulnerable cloud infrastructures. Through these entry points, TeamTNT aims to deploy the Sliver malware, and a cyber worm alongside cryptominers, using compromised servers and Docker Hub as pillars of their malicious ecosystem. This approach highlights the group’s adaptability and emphasizes the critical need for vigilant cloud security to thwart resource hijacking and malware spread.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox