• Landing Page
  • Shop
  • Contact
  • Privacy Policy
  • Login
  • Register
Upgrade
TrivDaily
">
  • WorldNew
    Pound

    Pound hits 37-year low against dollar

    Palm Trees - WIND

    Hurricane Tracker : Tropical Storm Hurricane Nine has the potential to reach Florida

    Prince of Wales - TrivDaily

    Princess Diana’s title has been passed on to the Duchess of Cambridge

    TrivDaily - King Charles Speech

    3 main points to be gleaned from King Charles first public speech

    Abdul Qadeer Khan: ‘Father of Pakistan’s nuclear bomb’ dies

    Abdul Qadeer Khan: ‘Father of Pakistan’s nuclear bomb’ dies

    The Afghanistan airport explosion came about beneathneath Biden however lines lower back to Trump

    The Afghanistan airport explosion came about beneathneath Biden however lines lower back to Trump

    Hibernian  beat Arsenal 2-1 in first preseason game on Easter Road

    Hibernian beat Arsenal 2-1 in first preseason game on Easter Road

    After a “racist” tweet against England black players, comedian Andrew Lawrence’s agent cancelled his appearance in show.

    After a “racist” tweet against England black players, comedian Andrew Lawrence’s agent cancelled his appearance in show.

    Lionel Messi, Argentina win Copa America over Brazil

    Lionel Messi, Argentina win Copa America over Brazil

    Trending Tags

    • Lifestyle
      UK weather maps show exact date 7cm of snow and 63mph winds to batter Britain

      UK weather maps show exact date 7cm of snow and 63mph winds to batter Britain

      bet365 bonus code: Secure £30 bonus for Atalanta vs Chelsea trip with code SUN365

      bet365 bonus code: Secure £30 bonus for Atalanta vs Chelsea trip with code SUN365

      Crystal Palace into Champions League places as Guehi scores late winner at Fulham

      UK snow maps show 3-day barrage hitting 10 counties with -6C freeze

      UK snow maps show 3-day barrage hitting 10 counties with -6C freeze

      Hundreds of Man Utd fans stuck outside Old Trafford for West Ham clash with turnstile chaos ‘worst ever seen’

      Hundreds of Man Utd fans stuck outside Old Trafford for West Ham clash with turnstile chaos ‘worst ever seen’

      ARTE and Suspilne Ukraine sign an association agreement to strengthen cooperation

      ARTE and Suspilne Ukraine sign an association agreement to strengthen cooperation

      Trending Tags

      • Pandemic
    • Business
      Danger to Life’ as Storm Bram Batters Devon and Cornwall With Flooding and 90mph Winds

      Danger to Life’ as Storm Bram Batters Devon and Cornwall With Flooding and 90mph Winds

      Zelensky Rushes to London as Trump Accuses Him Over Peace Plan and Kremlin Applauds US Pressure

      Zelensky Rushes to London as Trump Accuses Him Over Peace Plan and Kremlin Applauds US Pressure

      Transmasculine Non-Binary Identity Explained As XG’s Cocona Comes Out

      Transmasculine Non-Binary Identity Explained As XG’s Cocona Comes Out

      Damson Idris and Lori Harvey Ignite ‘Back Together’ Speculation After Unexpected PDA at Art Basel Miami

      Damson Idris and Lori Harvey Ignite ‘Back Together’ Speculation After Unexpected PDA at Art Basel Miami

      Chris Hemsworth, Elsa Pataky Divorce Rumours: Wedding Rings Off As Couple ‘Drift Apart’

      Chris Hemsworth, Elsa Pataky Divorce Rumours: Wedding Rings Off As Couple ‘Drift Apart’

      Miss Universe 2025 Scandal: Why Fatima Bosch Refuses to Step Down Amid Claims of a ‘Predetermined’ Victory

      Miss Universe 2025 Scandal: Why Fatima Bosch Refuses to Step Down Amid Claims of a ‘Predetermined’ Victory

      Trending Tags

      • Vaccine
      • Pandemic
    • Entertainment
      Court dismisses £1.5m problem gambling claim against Betfair for second time

      Court dismisses £1.5m problem gambling claim against Betfair for second time

      Sophia Thakur’s Lexicon Is Love

      Sophia Thakur’s Lexicon Is Love

      President Trump awards medals to Sly Stallone, George Strait and more

      President Trump awards medals to Sly Stallone, George Strait and more

      Supplier Supplement: fraudsters, storytelling and technology

      Supplier Supplement: fraudsters, storytelling and technology

      Fred again.. And Blanco Combine On ‘Solo’

      Fred again.. And Blanco Combine On ‘Solo’

      Moonstone Rings: A Timeless Addition to Your Jewelry Collection

      Moonstone Rings: A Timeless Addition to Your Jewelry Collection

      The six Latin American markets the betting industry should keep an eye on

      The six Latin American markets the betting industry should keep an eye on

      Denmark backs “Banko Bill” to set rules of radio & walkie-talkie bingo

      Denmark backs “Banko Bill” to set rules of radio & walkie-talkie bingo

      Peru escalates dispute of Dina’s tax encroachment 

      Peru escalates dispute of Dina’s tax encroachment 

      Trending Tags

      • Sports
        Dusty May: No. 2 Michigan ‘Deserves’ to Be No. 1 After Dominating Villanova

        Dusty May: No. 2 Michigan ‘Deserves’ to Be No. 1 After Dominating Villanova

        AJ Dybantsa’s Career Night, Robert Wright III’s GW Lifts No. 10 BYU Past Clemson

        AJ Dybantsa’s Career Night, Robert Wright III’s GW Lifts No. 10 BYU Past Clemson

        Gen Z Trades Doomscrolling for Real-World Sweat: Key Takeaways from Strava’s 12th Year in Sport Report

        Gen Z Trades Doomscrolling for Real-World Sweat: Key Takeaways from Strava’s 12th Year in Sport Report

        Eagles at Chargers Live Updates | Monday Night Football

        Eagles at Chargers Live Updates | Monday Night Football

        Stake Canada App — Download, Legality, Features & How-To (2025)

        Stake Canada App — Download, Legality, Features & How-To (2025)

        Buccaneers’ NFC South Chances Take Massive Hit After Loss to Saints

        Buccaneers’ NFC South Chances Take Massive Hit After Loss to Saints

        Dallas Cowboys may have found a late-round gem in WR Ryan Flournoy

        Dallas Cowboys may have found a late-round gem in WR Ryan Flournoy

        Cowboys 2025 rookie report: Rookie class was flat in battle against the Lions

        Cowboys 2025 rookie report: Rookie class was flat in battle against the Lions

        Rockets’ Kevin Durant Latest to Score 31K Career Points During Win vs. Suns

        Rockets’ Kevin Durant Latest to Score 31K Career Points During Win vs. Suns

        Trending Tags

        • Travel
          Football’s biggest names including Mbappe and Haaland rally behind Mohamed Salah after Liverpool axe

          Football’s biggest names including Mbappe and Haaland rally behind Mohamed Salah after Liverpool axe

          Man Utd face Premier League bogey side and Arsenal travel to former winners as full FA Cup Third Round draw revealed

          Man Utd face Premier League bogey side and Arsenal travel to former winners as full FA Cup Third Round draw revealed

          Finding stillness in Kyoto: My solo journey through Japan’s most peaceful retreats

          Finding stillness in Kyoto: My solo journey through Japan’s most peaceful retreats

          Saudi giants enquire about Liverpool star Salah

          Saudi giants enquire about Liverpool star Salah

          Christmas chaos warning as staff set to strike at major UK airport

          Christmas chaos warning as staff set to strike at major UK airport

          How volcanic eruptions brought the Black Death to Europe

          How volcanic eruptions brought the Black Death to Europe

          Trending Tags

          • Technology
            UK to Europe: The time to counter Russia’s information war machine is now

            UK to Europe: The time to counter Russia’s information war machine is now

            Affection for Excel spans generations, from Boomers to Zoomers

            Affection for Excel spans generations, from Boomers to Zoomers

            Trump’s EPA Plans to Raise Threshold for ‘Safe’ Formaldehyde Exposure

            Trump’s EPA Plans to Raise Threshold for ‘Safe’ Formaldehyde Exposure

            A New Meta Quest Probably Won’t Happen in 2026

            A New Meta Quest Probably Won’t Happen in 2026

            And the winner of the Microsoft Christmas sweater is…

            And the winner of the Microsoft Christmas sweater is…

            Death to one-time text codes: Passkeys are the new hotness in MFA

            Death to one-time text codes: Passkeys are the new hotness in MFA

            Trending Tags

            • Real Estate
              Malaysia Plans To Open Worldwide Tourism On December 1

              Malaysia Plans To Open Worldwide Tourism On December 1

              #1 UK housing: renting has turn out to be less expensive than shopping

              #1 UK housing: renting has turn out to be less expensive than shopping

              UK assets marketplace pastime maintains at record-breaking levels

              UK assets marketplace pastime maintains at record-breaking levels

              GUUD Launches New RYTE Financing Platform To Make Trade Finance Accessible for All Businesses

              GUUD Launches New RYTE Financing Platform To Make Trade Finance Accessible for All Businesses

              Climate Finance Partnership Raises US$250 Million at First Close to Invest in Emerging Market Climate Infrastructure

              Climate Finance Partnership Raises US$250 Million at First Close to Invest in Emerging Market Climate Infrastructure

              Interior Jennifer Lopez’s luxe Miami rental: 5 stress-free details in regards to the mansion

              Interior Jennifer Lopez’s luxe Miami rental: 5 stress-free details in regards to the mansion

              Trending Tags

              No Result
              View All Result
              • WorldNew
                Pound

                Pound hits 37-year low against dollar

                Palm Trees - WIND

                Hurricane Tracker : Tropical Storm Hurricane Nine has the potential to reach Florida

                Prince of Wales - TrivDaily

                Princess Diana’s title has been passed on to the Duchess of Cambridge

                TrivDaily - King Charles Speech

                3 main points to be gleaned from King Charles first public speech

                Abdul Qadeer Khan: ‘Father of Pakistan’s nuclear bomb’ dies

                Abdul Qadeer Khan: ‘Father of Pakistan’s nuclear bomb’ dies

                The Afghanistan airport explosion came about beneathneath Biden however lines lower back to Trump

                The Afghanistan airport explosion came about beneathneath Biden however lines lower back to Trump

                Hibernian  beat Arsenal 2-1 in first preseason game on Easter Road

                Hibernian beat Arsenal 2-1 in first preseason game on Easter Road

                After a “racist” tweet against England black players, comedian Andrew Lawrence’s agent cancelled his appearance in show.

                After a “racist” tweet against England black players, comedian Andrew Lawrence’s agent cancelled his appearance in show.

                Lionel Messi, Argentina win Copa America over Brazil

                Lionel Messi, Argentina win Copa America over Brazil

                Trending Tags

                • Lifestyle
                  UK weather maps show exact date 7cm of snow and 63mph winds to batter Britain

                  UK weather maps show exact date 7cm of snow and 63mph winds to batter Britain

                  bet365 bonus code: Secure £30 bonus for Atalanta vs Chelsea trip with code SUN365

                  bet365 bonus code: Secure £30 bonus for Atalanta vs Chelsea trip with code SUN365

                  Crystal Palace into Champions League places as Guehi scores late winner at Fulham

                  UK snow maps show 3-day barrage hitting 10 counties with -6C freeze

                  UK snow maps show 3-day barrage hitting 10 counties with -6C freeze

                  Hundreds of Man Utd fans stuck outside Old Trafford for West Ham clash with turnstile chaos ‘worst ever seen’

                  Hundreds of Man Utd fans stuck outside Old Trafford for West Ham clash with turnstile chaos ‘worst ever seen’

                  ARTE and Suspilne Ukraine sign an association agreement to strengthen cooperation

                  ARTE and Suspilne Ukraine sign an association agreement to strengthen cooperation

                  Trending Tags

                  • Pandemic
                • Business
                  Danger to Life’ as Storm Bram Batters Devon and Cornwall With Flooding and 90mph Winds

                  Danger to Life’ as Storm Bram Batters Devon and Cornwall With Flooding and 90mph Winds

                  Zelensky Rushes to London as Trump Accuses Him Over Peace Plan and Kremlin Applauds US Pressure

                  Zelensky Rushes to London as Trump Accuses Him Over Peace Plan and Kremlin Applauds US Pressure

                  Transmasculine Non-Binary Identity Explained As XG’s Cocona Comes Out

                  Transmasculine Non-Binary Identity Explained As XG’s Cocona Comes Out

                  Damson Idris and Lori Harvey Ignite ‘Back Together’ Speculation After Unexpected PDA at Art Basel Miami

                  Damson Idris and Lori Harvey Ignite ‘Back Together’ Speculation After Unexpected PDA at Art Basel Miami

                  Chris Hemsworth, Elsa Pataky Divorce Rumours: Wedding Rings Off As Couple ‘Drift Apart’

                  Chris Hemsworth, Elsa Pataky Divorce Rumours: Wedding Rings Off As Couple ‘Drift Apart’

                  Miss Universe 2025 Scandal: Why Fatima Bosch Refuses to Step Down Amid Claims of a ‘Predetermined’ Victory

                  Miss Universe 2025 Scandal: Why Fatima Bosch Refuses to Step Down Amid Claims of a ‘Predetermined’ Victory

                  Trending Tags

                  • Vaccine
                  • Pandemic
                • Entertainment
                  Court dismisses £1.5m problem gambling claim against Betfair for second time

                  Court dismisses £1.5m problem gambling claim against Betfair for second time

                  Sophia Thakur’s Lexicon Is Love

                  Sophia Thakur’s Lexicon Is Love

                  President Trump awards medals to Sly Stallone, George Strait and more

                  President Trump awards medals to Sly Stallone, George Strait and more

                  Supplier Supplement: fraudsters, storytelling and technology

                  Supplier Supplement: fraudsters, storytelling and technology

                  Fred again.. And Blanco Combine On ‘Solo’

                  Fred again.. And Blanco Combine On ‘Solo’

                  Moonstone Rings: A Timeless Addition to Your Jewelry Collection

                  Moonstone Rings: A Timeless Addition to Your Jewelry Collection

                  The six Latin American markets the betting industry should keep an eye on

                  The six Latin American markets the betting industry should keep an eye on

                  Denmark backs “Banko Bill” to set rules of radio & walkie-talkie bingo

                  Denmark backs “Banko Bill” to set rules of radio & walkie-talkie bingo

                  Peru escalates dispute of Dina’s tax encroachment 

                  Peru escalates dispute of Dina’s tax encroachment 

                  Trending Tags

                  • Sports
                    Dusty May: No. 2 Michigan ‘Deserves’ to Be No. 1 After Dominating Villanova

                    Dusty May: No. 2 Michigan ‘Deserves’ to Be No. 1 After Dominating Villanova

                    AJ Dybantsa’s Career Night, Robert Wright III’s GW Lifts No. 10 BYU Past Clemson

                    AJ Dybantsa’s Career Night, Robert Wright III’s GW Lifts No. 10 BYU Past Clemson

                    Gen Z Trades Doomscrolling for Real-World Sweat: Key Takeaways from Strava’s 12th Year in Sport Report

                    Gen Z Trades Doomscrolling for Real-World Sweat: Key Takeaways from Strava’s 12th Year in Sport Report

                    Eagles at Chargers Live Updates | Monday Night Football

                    Eagles at Chargers Live Updates | Monday Night Football

                    Stake Canada App — Download, Legality, Features & How-To (2025)

                    Stake Canada App — Download, Legality, Features & How-To (2025)

                    Buccaneers’ NFC South Chances Take Massive Hit After Loss to Saints

                    Buccaneers’ NFC South Chances Take Massive Hit After Loss to Saints

                    Dallas Cowboys may have found a late-round gem in WR Ryan Flournoy

                    Dallas Cowboys may have found a late-round gem in WR Ryan Flournoy

                    Cowboys 2025 rookie report: Rookie class was flat in battle against the Lions

                    Cowboys 2025 rookie report: Rookie class was flat in battle against the Lions

                    Rockets’ Kevin Durant Latest to Score 31K Career Points During Win vs. Suns

                    Rockets’ Kevin Durant Latest to Score 31K Career Points During Win vs. Suns

                    Trending Tags

                    • Travel
                      Football’s biggest names including Mbappe and Haaland rally behind Mohamed Salah after Liverpool axe

                      Football’s biggest names including Mbappe and Haaland rally behind Mohamed Salah after Liverpool axe

                      Man Utd face Premier League bogey side and Arsenal travel to former winners as full FA Cup Third Round draw revealed

                      Man Utd face Premier League bogey side and Arsenal travel to former winners as full FA Cup Third Round draw revealed

                      Finding stillness in Kyoto: My solo journey through Japan’s most peaceful retreats

                      Finding stillness in Kyoto: My solo journey through Japan’s most peaceful retreats

                      Saudi giants enquire about Liverpool star Salah

                      Saudi giants enquire about Liverpool star Salah

                      Christmas chaos warning as staff set to strike at major UK airport

                      Christmas chaos warning as staff set to strike at major UK airport

                      How volcanic eruptions brought the Black Death to Europe

                      How volcanic eruptions brought the Black Death to Europe

                      Trending Tags

                      • Technology
                        UK to Europe: The time to counter Russia’s information war machine is now

                        UK to Europe: The time to counter Russia’s information war machine is now

                        Affection for Excel spans generations, from Boomers to Zoomers

                        Affection for Excel spans generations, from Boomers to Zoomers

                        Trump’s EPA Plans to Raise Threshold for ‘Safe’ Formaldehyde Exposure

                        Trump’s EPA Plans to Raise Threshold for ‘Safe’ Formaldehyde Exposure

                        A New Meta Quest Probably Won’t Happen in 2026

                        A New Meta Quest Probably Won’t Happen in 2026

                        And the winner of the Microsoft Christmas sweater is…

                        And the winner of the Microsoft Christmas sweater is…

                        Death to one-time text codes: Passkeys are the new hotness in MFA

                        Death to one-time text codes: Passkeys are the new hotness in MFA

                        Trending Tags

                        • Real Estate
                          Malaysia Plans To Open Worldwide Tourism On December 1

                          Malaysia Plans To Open Worldwide Tourism On December 1

                          #1 UK housing: renting has turn out to be less expensive than shopping

                          #1 UK housing: renting has turn out to be less expensive than shopping

                          UK assets marketplace pastime maintains at record-breaking levels

                          UK assets marketplace pastime maintains at record-breaking levels

                          GUUD Launches New RYTE Financing Platform To Make Trade Finance Accessible for All Businesses

                          GUUD Launches New RYTE Financing Platform To Make Trade Finance Accessible for All Businesses

                          Climate Finance Partnership Raises US$250 Million at First Close to Invest in Emerging Market Climate Infrastructure

                          Climate Finance Partnership Raises US$250 Million at First Close to Invest in Emerging Market Climate Infrastructure

                          Interior Jennifer Lopez’s luxe Miami rental: 5 stress-free details in regards to the mansion

                          Interior Jennifer Lopez’s luxe Miami rental: 5 stress-free details in regards to the mansion

                          Trending Tags

                          No Result
                          View All Result
                          TrivDaily
                          No Result
                          View All Result
                          Home Technology

                          Infosec watchers: TeamTNT crew may blast holes in Azure, Google Cloud users

                          Ferhan Rana by Ferhan Rana
                          July 16, 2023
                          in Technology
                          Reading Time:4 mins read
                          30.5k 1.3k
                          A A
                          0
                          Infosec watchers: TeamTNT crew may blast holes in Azure, Google Cloud users
                          29.7k
                          SHARES
                          33.8k
                          VIEWS
                          Share on FacebookShare on Twitter
                          ">

                          A criminal crew with a history of deploying malware to harvest credentials from Amazon Web Services accounts may expand its attention to organizations using Microsoft Azure and Google Cloud Platform.

                          Researchers with SentinelOne, Permiso Security, and Aqua Security say a credential-stealing campaign, which began in June, includes the hallmarks of the notorious TeamTNT, though full attribution is difficult.

                          That said, given the amount of work the miscreants have done to improve their techniques and the addition of Azure and Google Cloud accounts to the list of targets, the group looks set to ramp up its attacks, according to Alex Delamotte, researcher with SentinelOne’s SentinelLabs unit.

                          Whoever the miscreants are, it appears they scrape cloud infrastructure credentials – such as AWS keys – from victims’ Jupyter programming notebooks; accessing those notebooks may require the exploitation of poorly secured web applications, or the notebooks may have been accidentally left open to the public, it seems. The crooks’ ultimate goal is to get credentials, use them to copy malware onto someone else’s cloud-based systems, and run that malware.

                          Once the crew’s code is executing on a victim’s resources, the intruders can run scripts on those remote systems that search for and harvest more access credentials, mine cryptocurrencies, open a backdoor, and potentially siphon off information or meddle with operations. The crooks used to target primarily AWS users, and now seem to be looking for ways into Azure and Google Cloud accounts.

                          “While AWS has long been in the crosshairs of many cloud-focused actors, the expansion to Azure and GCP credentials indicates there are other major contenders holding valuable data,” Delamotte wrote in a report this week.

                          “We believe this actor is actively tuning and improving their tools. Based on the tweaks observed across the past several weeks, the actor is likely preparing for larger scale campaigns.”

                          Permiso researcher Abian Morina reckoned on Wednesday a multi-cloud campaign may already be underway as of this week.

                          It is not entirely clear exactly how the miscreants break into people’s cloud resources: check the linked advisories for technical details and indicators of compromise, and use the given info to detect and stop any identifiable intrusions, we say.

                          Cloud credentials are a popular target

                          According a write-up last year from Elastic Security Labs, 33 percent of cyberattacks in the cloud use stolen credentials, something TeamTNT is known for. The group has been around since 2019, though two years ago it announced it was quitting. However Trend Micro said the crew, known for targeting cloud and container environments, was back in business as of late last year.

                          Permiso in December 2022 documented how TeamTNT was scouring Jupyter Notebook services primarily for AWS credentials. The miscreants appear to have started targeting vulnerable Docker deployments, too, and updated their intrusion tools.

                          Those updates have brought in support for obtaining Azure and Google Cloud credentials, made the scripts more modular to achieve more complex attacks, improved the credential harvesting, and brought in the curl command-line tool to exfiltrate data.

                          • AT&T Alien Labs warns of ‘zero or low detection’ for TeamTNT’s latest malware bundle
                          • FBI: BlackCat ransomware scratched 60-plus orgs
                          • Microsoft defends intrusive dialog in Visual Studio Code that asks if you really trust the code you’ve been working on
                          • Microsoft stole our stolen dark web data, says security outfit

                          In addition, the group previously hosted its command-and-control (C2) activities and files in an openly accessible directory on a single domain. Now the C2’s directory requires a hardcoded username and password to access, making it tougher to inspect and stop. This infrastructure, which previously used a Netherlands-based IP address, now runs across several subdomains.

                          The researchers also found an ELF binary built from Golang source code; this executable is used to spread the malware to other vulnerable targets, seemingly in a worm-like fashion. The miscreants hide this system scanner as an embedded base64 object within the binary to make it more difficult to detect.

                          Something wicked this way comes

                          The latest campaign “demonstrates the evolution of a seasoned cloud actor with familiarity across many technologies,” Delamotte wrote.

                          “The meticulous attention to detail indicates the actor has clearly experienced plenty of trial and error. The actor has also improved the tool’s data formatting to enable more autonomous activity, which demonstrates a certain level of maturity and skill.”

                          The work SentinelLabs and Permiso echoes what Aqua uncovered earlier this month in connection with a “potentially massive campaign against cloud native environments” that researchers Ofek Itach and Assaf Morag laid at the feet of TeamTNT or a group using the same techniques.

                          Their investigation kicked off after an attack was detected against a Jupyter honeypot run by Aqua, and led to an examination of a container image and Docker Hub account, they wrote. They described the Silentbob campaign as an “aggressive cloud worm, designed to deploy on exposed JupyterLab and Docker APIs in order to deploy Tsunami malware, cloud credentials hijack, resource hijack and further infestation of the worm.”

                          Like SentinelLabs, the Aqua researchers said it appeared that what they were looking at was a trial run for a bigger operation.

                          “Given that some functions in the code remain unused and the linked attack patterns suggest manual testing, we theorize that the attacker is in the process of optimizing their algorithm,” they wrote at the start of July.

                          “Looks like TeamTNT or a TeamTNT copycat is preparing a campaign. We treat this as an early warning, and hopefully a prevention to the campaign.”

                          Aqua and SentinelLabs recommended enterprises protect themselves against such attacks by taking such steps as not deploying Jupyter software without authentication, properly configuring and patching web applications to minimize exploitation, restricting external access to Docker, and using the least-privilege principle by limiting the permissions of containers. ®

                          ">

                          A criminal crew with a history of deploying malware to harvest credentials from Amazon Web Services accounts may expand its attention to organizations using Microsoft Azure and Google Cloud Platform.

                          Researchers with SentinelOne, Permiso Security, and Aqua Security say a credential-stealing campaign, which began in June, includes the hallmarks of the notorious TeamTNT, though full attribution is difficult.

                          That said, given the amount of work the miscreants have done to improve their techniques and the addition of Azure and Google Cloud accounts to the list of targets, the group looks set to ramp up its attacks, according to Alex Delamotte, researcher with SentinelOne’s SentinelLabs unit.

                          Whoever the miscreants are, it appears they scrape cloud infrastructure credentials – such as AWS keys – from victims’ Jupyter programming notebooks; accessing those notebooks may require the exploitation of poorly secured web applications, or the notebooks may have been accidentally left open to the public, it seems. The crooks’ ultimate goal is to get credentials, use them to copy malware onto someone else’s cloud-based systems, and run that malware.

                          Once the crew’s code is executing on a victim’s resources, the intruders can run scripts on those remote systems that search for and harvest more access credentials, mine cryptocurrencies, open a backdoor, and potentially siphon off information or meddle with operations. The crooks used to target primarily AWS users, and now seem to be looking for ways into Azure and Google Cloud accounts.

                          “While AWS has long been in the crosshairs of many cloud-focused actors, the expansion to Azure and GCP credentials indicates there are other major contenders holding valuable data,” Delamotte wrote in a report this week.

                          “We believe this actor is actively tuning and improving their tools. Based on the tweaks observed across the past several weeks, the actor is likely preparing for larger scale campaigns.”

                          Permiso researcher Abian Morina reckoned on Wednesday a multi-cloud campaign may already be underway as of this week.

                          It is not entirely clear exactly how the miscreants break into people’s cloud resources: check the linked advisories for technical details and indicators of compromise, and use the given info to detect and stop any identifiable intrusions, we say.

                          Cloud credentials are a popular target

                          According a write-up last year from Elastic Security Labs, 33 percent of cyberattacks in the cloud use stolen credentials, something TeamTNT is known for. The group has been around since 2019, though two years ago it announced it was quitting. However Trend Micro said the crew, known for targeting cloud and container environments, was back in business as of late last year.

                          Permiso in December 2022 documented how TeamTNT was scouring Jupyter Notebook services primarily for AWS credentials. The miscreants appear to have started targeting vulnerable Docker deployments, too, and updated their intrusion tools.

                          Those updates have brought in support for obtaining Azure and Google Cloud credentials, made the scripts more modular to achieve more complex attacks, improved the credential harvesting, and brought in the curl command-line tool to exfiltrate data.

                          • AT&T Alien Labs warns of ‘zero or low detection’ for TeamTNT’s latest malware bundle
                          • FBI: BlackCat ransomware scratched 60-plus orgs
                          • Microsoft defends intrusive dialog in Visual Studio Code that asks if you really trust the code you’ve been working on
                          • Microsoft stole our stolen dark web data, says security outfit

                          In addition, the group previously hosted its command-and-control (C2) activities and files in an openly accessible directory on a single domain. Now the C2’s directory requires a hardcoded username and password to access, making it tougher to inspect and stop. This infrastructure, which previously used a Netherlands-based IP address, now runs across several subdomains.

                          The researchers also found an ELF binary built from Golang source code; this executable is used to spread the malware to other vulnerable targets, seemingly in a worm-like fashion. The miscreants hide this system scanner as an embedded base64 object within the binary to make it more difficult to detect.

                          Something wicked this way comes

                          The latest campaign “demonstrates the evolution of a seasoned cloud actor with familiarity across many technologies,” Delamotte wrote.

                          “The meticulous attention to detail indicates the actor has clearly experienced plenty of trial and error. The actor has also improved the tool’s data formatting to enable more autonomous activity, which demonstrates a certain level of maturity and skill.”

                          The work SentinelLabs and Permiso echoes what Aqua uncovered earlier this month in connection with a “potentially massive campaign against cloud native environments” that researchers Ofek Itach and Assaf Morag laid at the feet of TeamTNT or a group using the same techniques.

                          Their investigation kicked off after an attack was detected against a Jupyter honeypot run by Aqua, and led to an examination of a container image and Docker Hub account, they wrote. They described the Silentbob campaign as an “aggressive cloud worm, designed to deploy on exposed JupyterLab and Docker APIs in order to deploy Tsunami malware, cloud credentials hijack, resource hijack and further infestation of the worm.”

                          Like SentinelLabs, the Aqua researchers said it appeared that what they were looking at was a trial run for a bigger operation.

                          “Given that some functions in the code remain unused and the linked attack patterns suggest manual testing, we theorize that the attacker is in the process of optimizing their algorithm,” they wrote at the start of July.

                          “Looks like TeamTNT or a TeamTNT copycat is preparing a campaign. We treat this as an early warning, and hopefully a prevention to the campaign.”

                          Aqua and SentinelLabs recommended enterprises protect themselves against such attacks by taking such steps as not deploying Jupyter software without authentication, properly configuring and patching web applications to minimize exploitation, restricting external access to Docker, and using the least-privilege principle by limiting the permissions of containers. ®

                          ">

                          A criminal crew with a history of deploying malware to harvest credentials from Amazon Web Services accounts may expand its attention to organizations using Microsoft Azure and Google Cloud Platform.

                          Researchers with SentinelOne, Permiso Security, and Aqua Security say a credential-stealing campaign, which began in June, includes the hallmarks of the notorious TeamTNT, though full attribution is difficult.

                          That said, given the amount of work the miscreants have done to improve their techniques and the addition of Azure and Google Cloud accounts to the list of targets, the group looks set to ramp up its attacks, according to Alex Delamotte, researcher with SentinelOne’s SentinelLabs unit.

                          Whoever the miscreants are, it appears they scrape cloud infrastructure credentials – such as AWS keys – from victims’ Jupyter programming notebooks; accessing those notebooks may require the exploitation of poorly secured web applications, or the notebooks may have been accidentally left open to the public, it seems. The crooks’ ultimate goal is to get credentials, use them to copy malware onto someone else’s cloud-based systems, and run that malware.

                          Once the crew’s code is executing on a victim’s resources, the intruders can run scripts on those remote systems that search for and harvest more access credentials, mine cryptocurrencies, open a backdoor, and potentially siphon off information or meddle with operations. The crooks used to target primarily AWS users, and now seem to be looking for ways into Azure and Google Cloud accounts.

                          “While AWS has long been in the crosshairs of many cloud-focused actors, the expansion to Azure and GCP credentials indicates there are other major contenders holding valuable data,” Delamotte wrote in a report this week.

                          “We believe this actor is actively tuning and improving their tools. Based on the tweaks observed across the past several weeks, the actor is likely preparing for larger scale campaigns.”

                          Permiso researcher Abian Morina reckoned on Wednesday a multi-cloud campaign may already be underway as of this week.

                          It is not entirely clear exactly how the miscreants break into people’s cloud resources: check the linked advisories for technical details and indicators of compromise, and use the given info to detect and stop any identifiable intrusions, we say.

                          Cloud credentials are a popular target

                          According a write-up last year from Elastic Security Labs, 33 percent of cyberattacks in the cloud use stolen credentials, something TeamTNT is known for. The group has been around since 2019, though two years ago it announced it was quitting. However Trend Micro said the crew, known for targeting cloud and container environments, was back in business as of late last year.

                          Permiso in December 2022 documented how TeamTNT was scouring Jupyter Notebook services primarily for AWS credentials. The miscreants appear to have started targeting vulnerable Docker deployments, too, and updated their intrusion tools.

                          Those updates have brought in support for obtaining Azure and Google Cloud credentials, made the scripts more modular to achieve more complex attacks, improved the credential harvesting, and brought in the curl command-line tool to exfiltrate data.

                          • AT&T Alien Labs warns of ‘zero or low detection’ for TeamTNT’s latest malware bundle
                          • FBI: BlackCat ransomware scratched 60-plus orgs
                          • Microsoft defends intrusive dialog in Visual Studio Code that asks if you really trust the code you’ve been working on
                          • Microsoft stole our stolen dark web data, says security outfit

                          In addition, the group previously hosted its command-and-control (C2) activities and files in an openly accessible directory on a single domain. Now the C2’s directory requires a hardcoded username and password to access, making it tougher to inspect and stop. This infrastructure, which previously used a Netherlands-based IP address, now runs across several subdomains.

                          The researchers also found an ELF binary built from Golang source code; this executable is used to spread the malware to other vulnerable targets, seemingly in a worm-like fashion. The miscreants hide this system scanner as an embedded base64 object within the binary to make it more difficult to detect.

                          Something wicked this way comes

                          The latest campaign “demonstrates the evolution of a seasoned cloud actor with familiarity across many technologies,” Delamotte wrote.

                          “The meticulous attention to detail indicates the actor has clearly experienced plenty of trial and error. The actor has also improved the tool’s data formatting to enable more autonomous activity, which demonstrates a certain level of maturity and skill.”

                          The work SentinelLabs and Permiso echoes what Aqua uncovered earlier this month in connection with a “potentially massive campaign against cloud native environments” that researchers Ofek Itach and Assaf Morag laid at the feet of TeamTNT or a group using the same techniques.

                          Their investigation kicked off after an attack was detected against a Jupyter honeypot run by Aqua, and led to an examination of a container image and Docker Hub account, they wrote. They described the Silentbob campaign as an “aggressive cloud worm, designed to deploy on exposed JupyterLab and Docker APIs in order to deploy Tsunami malware, cloud credentials hijack, resource hijack and further infestation of the worm.”

                          Like SentinelLabs, the Aqua researchers said it appeared that what they were looking at was a trial run for a bigger operation.

                          “Given that some functions in the code remain unused and the linked attack patterns suggest manual testing, we theorize that the attacker is in the process of optimizing their algorithm,” they wrote at the start of July.

                          “Looks like TeamTNT or a TeamTNT copycat is preparing a campaign. We treat this as an early warning, and hopefully a prevention to the campaign.”

                          Aqua and SentinelLabs recommended enterprises protect themselves against such attacks by taking such steps as not deploying Jupyter software without authentication, properly configuring and patching web applications to minimize exploitation, restricting external access to Docker, and using the least-privilege principle by limiting the permissions of containers. ®

                          ">

                          A criminal crew with a history of deploying malware to harvest credentials from Amazon Web Services accounts may expand its attention to organizations using Microsoft Azure and Google Cloud Platform.

                          Researchers with SentinelOne, Permiso Security, and Aqua Security say a credential-stealing campaign, which began in June, includes the hallmarks of the notorious TeamTNT, though full attribution is difficult.

                          That said, given the amount of work the miscreants have done to improve their techniques and the addition of Azure and Google Cloud accounts to the list of targets, the group looks set to ramp up its attacks, according to Alex Delamotte, researcher with SentinelOne’s SentinelLabs unit.

                          Whoever the miscreants are, it appears they scrape cloud infrastructure credentials – such as AWS keys – from victims’ Jupyter programming notebooks; accessing those notebooks may require the exploitation of poorly secured web applications, or the notebooks may have been accidentally left open to the public, it seems. The crooks’ ultimate goal is to get credentials, use them to copy malware onto someone else’s cloud-based systems, and run that malware.

                          Once the crew’s code is executing on a victim’s resources, the intruders can run scripts on those remote systems that search for and harvest more access credentials, mine cryptocurrencies, open a backdoor, and potentially siphon off information or meddle with operations. The crooks used to target primarily AWS users, and now seem to be looking for ways into Azure and Google Cloud accounts.

                          “While AWS has long been in the crosshairs of many cloud-focused actors, the expansion to Azure and GCP credentials indicates there are other major contenders holding valuable data,” Delamotte wrote in a report this week.

                          “We believe this actor is actively tuning and improving their tools. Based on the tweaks observed across the past several weeks, the actor is likely preparing for larger scale campaigns.”

                          Permiso researcher Abian Morina reckoned on Wednesday a multi-cloud campaign may already be underway as of this week.

                          It is not entirely clear exactly how the miscreants break into people’s cloud resources: check the linked advisories for technical details and indicators of compromise, and use the given info to detect and stop any identifiable intrusions, we say.

                          Cloud credentials are a popular target

                          According a write-up last year from Elastic Security Labs, 33 percent of cyberattacks in the cloud use stolen credentials, something TeamTNT is known for. The group has been around since 2019, though two years ago it announced it was quitting. However Trend Micro said the crew, known for targeting cloud and container environments, was back in business as of late last year.

                          Permiso in December 2022 documented how TeamTNT was scouring Jupyter Notebook services primarily for AWS credentials. The miscreants appear to have started targeting vulnerable Docker deployments, too, and updated their intrusion tools.

                          Those updates have brought in support for obtaining Azure and Google Cloud credentials, made the scripts more modular to achieve more complex attacks, improved the credential harvesting, and brought in the curl command-line tool to exfiltrate data.

                          • AT&T Alien Labs warns of ‘zero or low detection’ for TeamTNT’s latest malware bundle
                          • FBI: BlackCat ransomware scratched 60-plus orgs
                          • Microsoft defends intrusive dialog in Visual Studio Code that asks if you really trust the code you’ve been working on
                          • Microsoft stole our stolen dark web data, says security outfit

                          In addition, the group previously hosted its command-and-control (C2) activities and files in an openly accessible directory on a single domain. Now the C2’s directory requires a hardcoded username and password to access, making it tougher to inspect and stop. This infrastructure, which previously used a Netherlands-based IP address, now runs across several subdomains.

                          The researchers also found an ELF binary built from Golang source code; this executable is used to spread the malware to other vulnerable targets, seemingly in a worm-like fashion. The miscreants hide this system scanner as an embedded base64 object within the binary to make it more difficult to detect.

                          Something wicked this way comes

                          The latest campaign “demonstrates the evolution of a seasoned cloud actor with familiarity across many technologies,” Delamotte wrote.

                          “The meticulous attention to detail indicates the actor has clearly experienced plenty of trial and error. The actor has also improved the tool’s data formatting to enable more autonomous activity, which demonstrates a certain level of maturity and skill.”

                          The work SentinelLabs and Permiso echoes what Aqua uncovered earlier this month in connection with a “potentially massive campaign against cloud native environments” that researchers Ofek Itach and Assaf Morag laid at the feet of TeamTNT or a group using the same techniques.

                          Their investigation kicked off after an attack was detected against a Jupyter honeypot run by Aqua, and led to an examination of a container image and Docker Hub account, they wrote. They described the Silentbob campaign as an “aggressive cloud worm, designed to deploy on exposed JupyterLab and Docker APIs in order to deploy Tsunami malware, cloud credentials hijack, resource hijack and further infestation of the worm.”

                          Like SentinelLabs, the Aqua researchers said it appeared that what they were looking at was a trial run for a bigger operation.

                          “Given that some functions in the code remain unused and the linked attack patterns suggest manual testing, we theorize that the attacker is in the process of optimizing their algorithm,” they wrote at the start of July.

                          “Looks like TeamTNT or a TeamTNT copycat is preparing a campaign. We treat this as an early warning, and hopefully a prevention to the campaign.”

                          Aqua and SentinelLabs recommended enterprises protect themselves against such attacks by taking such steps as not deploying Jupyter software without authentication, properly configuring and patching web applications to minimize exploitation, restricting external access to Docker, and using the least-privilege principle by limiting the permissions of containers. ®

                          Tags: Infosecwatchers
                          ">
                          Ferhan Rana

                          Ferhan Rana

                          Related Posts

                          It’s Probably a Bit Much to Say This AI Agent Cyberbullied a Developer By Blogging About Him
                          Technology

                          It’s Probably a Bit Much to Say This AI Agent Cyberbullied a Developer By Blogging About Him

                          by Ferhan Rana
                          February 18, 2026
                          Because of AI, Western Digital Hard Drives Are Sold Out
                          Technology

                          Because of AI, Western Digital Hard Drives Are Sold Out

                          by Ferhan Rana
                          February 18, 2026
                          Former NPR Host Accuses Google Of Copying His Voice For AI Offering
                          Technology

                          Former NPR Host Accuses Google Of Copying His Voice For AI Offering

                          by Ferhan Rana
                          February 17, 2026
                          Slow Adoption of iOS 26 on iPhones May Have Unexpectedly Hurt Tesla’s Sales: Report
                          Technology

                          Slow Adoption of iOS 26 on iPhones May Have Unexpectedly Hurt Tesla’s Sales: Report

                          by Ferhan Rana
                          February 17, 2026
                          Reddit, Meta, and Google Voluntarily Gave DHS Info of Anti-ICE Users, Report Says
                          Technology

                          Reddit, Meta, and Google Voluntarily Gave DHS Info of Anti-ICE Users, Report Says

                          by Ferhan Rana
                          February 16, 2026

                          Premium Content

                          Princess Theodora and Matthew Kumar look so in love in official wedding photos

                          Princess Theodora and Matthew Kumar look so in love in official wedding photos

                          September 29, 2024
                          World of Warcraft‘s Developers Just Made a Huge Leap Forward For Video Game Unionization

                          World of Warcraft‘s Developers Just Made a Huge Leap Forward For Video Game Unionization

                          July 25, 2024
                          Man United vs. Tottenham odds: Free 2025 UEFA Europa League final picks, prediction for Wednesday, May 21

                          Man United vs. Tottenham odds: Free 2025 UEFA Europa League final picks, prediction for Wednesday, May 21

                          May 21, 2025

                          Browse by Category

                          • Business
                          • Crypto
                          • Entertainment
                          • Fashion
                          • Health
                          • Lifestyle
                          • Real Estate
                          • Sports
                          • Technology
                          • Travel
                          • Uncategorized
                          • World

                          Browse by Tags

                          announces Apple Barcelona Beckham Charles Elizabeth Europe Exclusive family First George Google Harry health Inside Intel James Jennifer Kelly Lewis makes Manchester Markle Meghan Michael Microsoft Middleton people Prince Princess Queen REPORT reveals Review Royal Samsung Shares Taylor Trump Twitter wants WATCH William World Years
                          TrivDaily

                          Get the latest World news and analysis, breaking news, features and special reports from World. Also watch videos from across the Europian continent.

                          Learn more

                          Categories

                          • Business
                          • Crypto
                          • Entertainment
                          • Fashion
                          • Health
                          • Lifestyle
                          • Real Estate
                          • Sports
                          • Technology
                          • Travel
                          • Uncategorized
                          • World

                          Browse by Tag

                          Business (1525) Crypto (1593) Entertainment (1947) Fashion (3) Health (1787) Lifestyle (1850) Real Estate (40) Sports (3000) Technology (2979) Travel (1440) Uncategorized (11) World (23)

                          Recent Posts

                          • Arlington SX Full Race Day and TV Broadcast Schedules
                          • Jordon Smith Set for Season, 450SX Debut at Arlington SX
                          • UK Online Casino: A Modern Guide

                          © 2021 TrivDaily - Developed by ADSA Solutions.

                          Welcome Back!

                          Login to your account below

                          Forgotten Password? Sign Up

                          Create New Account!

                          Fill the forms bellow to register

                          All fields are required. Log In

                          Retrieve your password

                          Please enter your username or email address to reset your password.

                          Log In

                          Add New Playlist

                          • Login
                          • Sign Up
                          • Cart
                          No Result
                          View All Result
                          • Home
                          • Business News
                          • Entertainment News
                          • Lifestyle News
                          • Health News
                          • Tech News
                          • Real Estate News
                          • World News

                          © 2021 TrivDaily - Developed by ADSA Solutions.

                          Are you sure want to unlock this post?
                          Unlock left : 0
                          Are you sure want to cancel subscription?