Skip to main content

TeamTNT is the first cryptomining bot that steals AWS credentials

  • August 18, 2020
  • 2 replies
  • 27 views

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

August 18, 2020  By Pierluigi Paganini

 

Security researchers have discovered a new crypto-minining botnet, dubbed TeamTNT, that is able to steal AWS credentials from infected servers.

Security firm Cado Security reported that the TeamTNT botnet is the first one that is able to scan and steal AWS credentials.

The TeamTNT botnet is a crypto-mining malware operation that has been active since April and that targets Docker installs.

The activity of the TeamTNT group has been detailed by security firm Trend Micro, but the new feature was added only recently.

 

Full Article.

2 replies

TripleHelix
Moderator
Forum|alt.badge.img+63
  • Moderator
  • August 18, 2020

WSA uses AWS….. “ The botnet operators have added a new feature that scans the underlying infected servers for any Amazon Web Services (AWS) credentials.” Is Webroot safe @DanP  :wink:

 

Thanks,


DanP
Forum|alt.badge.img+35
  • OpenText Employee
  • August 18, 2020

WSA uses AWS….. “ The botnet operators have added a new feature that scans the underlying infected servers for any Amazon Web Services (AWS) credentials.” Is Webroot safe @DanP  :wink:

 

Thanks,

 

@TripleHelix,

 

This targets misconfigured installations, and the new feature scans for AWS credentials in unencrypted files. We should be safe from this.

 

-Dan