TeamTNT, a cryptojacking group, is preparing for a large-scale campaign targeting cloud-native environments for mining cryptocurrencies. They are using Docker daemons to deploy malware and cryptominers, as well as renting out breached servers for illicit cryptocurrency mining. The attacks involve identifying exposed Docker API endpoints, deploying malicious containers, and using the Sliver C2 framework for remote control. Additionally, another campaign involving the Prometei crypto mining botnet is targeting vulnerabilities in RDP and SMB to mine cryptocurrencies without the victim’s knowledge. This highlights the evolving tactics of threat actors in exploiting cloud environments for financial gain.
read full article
We do not own the rights to this content & no infringement intended, CREDIT: The Original Source: thehackernews.com
Trendzz Only Comment:
This
.