• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Sunday, September 14, 2025
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

Cryptojacking Group TeamTNT Suspected of Using Decoy Miner to Conceal Data Exfiltration

16 March 2023
in Mining
Reading Time: 5 mins read
A A
0
Cryptojacking Group TeamTNT Suspected of Using Decoy Miner to Conceal Data Exfiltration
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT

Related articles

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024
Cryptohopper
ADVERTISEMENT

Mar 16, 2023Ravie LakshmananCryptojacking / Cyber Attack

The cryptojacking group known as TeamTNT is suspected to be behind a previously undiscovered strain of malware used to mine Monero cryptocurrency on compromised systems.

That’s according to Cado Security, which found the sample after Sysdig detailed a sophisticated attack known as SCARLETEEL aimed at containerized environments to ultimately steal proprietary data and software.

Specifically, the early phase of the attack chain involved the use of a cryptocurrency miner, which the cloud security firm suspected was deployed as a decoy to conceal the detection of data exfiltration.

The artifact – uploaded to VirusTotal late last month – “bear[s] several syntactic and semantic similarities to prior TeamTNT payloads, and includes a wallet ID that has previously been attributed to them,” a new analysis from Cado Security has revealed.

TeamTNT, active since at least 2019, has been documented to repeatedly strike cloud and container environments to deploy cryptocurrency miners. It’s also known to unleash a crypto mining worm capable of stealing AWS credentials.

While the threat actor willingly shut down their operations in November 2021, cloud security firm Aqua disclosed in September 2022 a fresh set of attacks mounted by the group targeting misconfigured Docker and Redis instances.

That said, there are also indications that rival crews such as WatchDog might be mimicking TeamTNT’s tactics, techniques, and procedures (TTPs) to foil attribution efforts.

Another activity cluster of note is Kiss-a-dog, which also relies on tools and command-and-control (C2) infrastructure previously associated with TeamTNT to mine cryptocurrency.

There is no concrete evidence to tie the new malware to the SCARLETEEL attack. But Cado Security pointed out that the sample surfaced around the same time the latter was reported, raising the possibility that this could be the “decoy” miner that was installed.

The shell script, for its part, takes preparatory steps to reconfigure resource hard limits, prevent command history logging, accept all ingress or egress traffic, enumerate hardware resources, and even clean up prior compromises before commencing the activity.

Like other TeamTNT-linked attacks, the malicious payload also leverages a technique referred to as dynamic linker hijacking to cloak the miner process via a shared object executable called libprocesshider that uses the LD_PRELOAD environment variable.

Persistence is achieved by three different means, one of which modifies the .profile file, to ensure that the miner continues to run across system reboots.

WEBINAR

Discover the Hidden Dangers of Third-Party SaaS Apps

Are you aware of the risks associated with third-party app access to your company’s SaaS apps? Join our webinar to learn about the types of permissions being granted and how to minimize risk.

RESERVE YOUR SEAT

The findings come as another crypto miner group dubbed the 8220 Gang has been observed using a crypter called ScrubCrypt to carry out illicit cryptojacking operations.

What’s more, unknown threat actors have been found targeting vulnerable Kubernetes container orchestrator infrastructure with exposed APIs to mine the Dero cryptocurrency, marking a shift from Monero.

Cybersecurity company Morphisec, last month, also shed light on an evasive malware campaign that leverages the ProxyShell vulnerabilities in Microsoft Exchange servers to drop a crypto miner strain codenamed ProxyShellMiner.

“Mining cryptocurrency on an organization’s network can lead to system performance degradation, increased power consumption, equipment overheating, and can stop services,” the researchers said. “It allows threat actors access for even more nefarious ends.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.



Source link

[crypto-donation-box]
Tags: ConcealCryptoJackingDataDecoyExfiltrationGroupMinerSuspectedTeamTNT
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

Shiba Vs Floki | CryptoTvplus: DeFi, NFT, Bitcoin, Ethereum Altcoin, Cryptocurrency & Blockchain News, Interviews, Research, Shows

Next Post

Web3 Company Orange Comet Taps 13-Year-Old Artist Doodle Boy for NFT Drop

Related Posts

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
0

A fake news story circulated today about Russia’s supposed embrace of bitcoin mining and crypto payments. According to excited social...

New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024
0

A new report estimates a $20 billion revenue opportunity in Bitcoin BTC/USD mining chips and hardware over the next five...

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

30 July 2024
0

(Bloomberg) -- Russia is moving to regulate the use of cryptocurrencies, as companies wrestle with increasing difficulties in foreign payments...

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

30 July 2024
0

The Russian central bank plans to initiate international payments in cryptocurrencies by the end of the year to overcome delays...

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

30 July 2024
0

Listed both on Wall Street and the London Stock Exchange (LSE) Bitcoin miner Argo Blockchain, has announced a £6.5 million...

Load More
Next Post
Web3 Company Orange Comet Taps 13-Year-Old Artist Doodle Boy for NFT Drop

Web3 Company Orange Comet Taps 13-Year-Old Artist Doodle Boy for NFT Drop

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
0 BNB Peak Stuns The Financial World – Cointribune

$940 BNB Peak Stuns The Financial World – Cointribune

14 September 2025
Big Solana News: Nasdaq Approval Could Spark Major Price Surge – TechFinancials

Big Solana News: Nasdaq Approval Could Spark Major Price Surge – TechFinancials

14 September 2025
$BNB Hits New All-Time High At 9, Driving DeFi And Institutional Adoption – BlockchainReporter

$BNB Hits New All-Time High At $929, Driving DeFi And Institutional Adoption – BlockchainReporter

14 September 2025
Bitcoin Investors Are Back In The Market—Why A Momentum-Driven Rally May Be Near

Bitcoin Investors Are Back In The Market—Why A Momentum-Driven Rally May Be Near

13 September 2025

About Us

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • $940 BNB Peak Stuns The Financial World – Cointribune
  • Big Solana News: Nasdaq Approval Could Spark Major Price Surge – TechFinancials
  • $BNB Hits New All-Time High At $929, Driving DeFi And Institutional Adoption – BlockchainReporter
  • Bitcoin Investors Are Back In The Market—Why A Momentum-Driven Rally May Be Near
  • Solana price prediction: Can Sol hit new highs before October? Analysts hint to keep watch on RTX for major gains – Latest news from Azerbaijan

Subscribe Now

Our Partner

Round Main Logo
  • About Us
  • Privacy Policy
  • Contact Us

© 2022-2025 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin (BTC) $ 115,817.00
  • ethereumEthereum (ETH) $ 4,667.30
  • xrpXRP (XRP) $ 3.09
  • tetherTether (USDT) $ 1.00
  • solanaSolana (SOL) $ 246.98
  • bnbBNB (BNB) $ 939.37
  • usd-coinUSDC (USDC) $ 0.999808
  • dogecoinDogecoin (DOGE) $ 0.290396
  • staked-etherLido Staked Ether (STETH) $ 4,653.35
  • cardanoCardano (ADA) $ 0.917235
  • tronTRON (TRX) $ 0.350541
  • wrapped-stethWrapped stETH (WSTETH) $ 5,646.07
  • chainlinkChainlink (LINK) $ 24.72
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 5,029.42
  • hyperliquidHyperliquid (HYPE) $ 54.74
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 115,758.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • suiSui (SUI) $ 3.76
  • avalanche-2Avalanche (AVAX) $ 30.17
  • stellarStellar (XLM) $ 0.397671
  • wrapped-eethWrapped eETH (WEETH) $ 5,010.27
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.00
  • bitcoin-cashBitcoin Cash (BCH) $ 592.59
  • wethWETH (WETH) $ 4,664.57
  • hedera-hashgraphHedera (HBAR) $ 0.243717
  • litecoinLitecoin (LTC) $ 117.13
  • leo-tokenLEO Token (LEO) $ 9.52
  • the-open-networkToncoin (TON) $ 3.24
  • crypto-com-chainCronos (CRO) $ 0.246102
  • shiba-inuShiba Inu (SHIB) $ 0.000014
  • usdsUSDS (USDS) $ 0.999616
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • polkadotPolkadot (DOT) $ 4.42
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 115,791.00
  • whitebitWhiteBIT Coin (WBT) $ 44.21
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.223468
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • uniswapUniswap (UNI) $ 9.71
  • mantleMantle (MNT) $ 1.65
  • moneroMonero (XMR) $ 288.45
  • ethenaEthena (ENA) $ 0.748721
  • pepePepe (PEPE) $ 0.000012
  • aaveAave (AAVE) $ 310.64
  • bitget-tokenBitget Token (BGB) $ 5.02
  • daiDai (DAI) $ 0.999925
  • okbOKB (OKB) $ 203.41
  • memecoreMemeCore (M) $ 2.49
  • jito-staked-solJito Staked SOL (JITOSOL) $ 303.43
  • worldcoin-wldWorldcoin (WLD) $ 1.72
  • nearNEAR Protocol (NEAR) $ 2.77