TeamTNT’s Cloud Credential Stealing Campaign Now Targets Azure and Google Cloud


A malicious actor has been linked to a cloud credential stealing campaign in June 2023 that’s focused on Azure and Google Cloud Platform (GCP) services, marking the adversary’s expansion in targeting beyond Amazon Web Services (AWS).

The findings come from SentinelOne and Permiso, which said the “campaigns share similarity with tools attributed to the notorious TeamTNT cryptojacking crew,” although it emphasized that “attribution remains challenging with script-based tools.”

They also overlap with an ongoing TeamTNT campaign disclosed by Aqua called Silentbob that leverages misconfigured cloud services to drop malware as part of what’s said to be a testing effort, while also linking SCARLETEEL attacks to the threat actor, citing infrastructure commonalities.

Read more…