10 Team TNT

Team TNT

Region
Asia-Pacific, 
Europe
Industries
Banking
First seen
August 2020
Cybercrime
Significant cryptojacking, causing a huge amount in victim expenses
Heritage
Appeared in 2020 and disappeared in 2022 before re-emerging
Categorizations
Cloud-based crypto crime
About

These Masked Actors are infamous for cloud-targeted cryptojacking, Secure Shell (SSH) brute-force attacks, and data theft. Over the years, Team TNT, has developed new tools to hunt more victims while operating in the shadows. In 2022, Team TNT abruptly vanished, then re-emerged in 2023.

Learn more about Team TNT from Group-IB’s research
Victims

We’ve attributed over $8,100 in mined cryptocurrency, causing a huge amount in victim expenses ($430,000). Team TNT has launched long-term campaigns, targeting vulnerable public instances of Redis, Kubernetes, and Docker.

What we know about Team TNT members

No known identities. However, our analysts have identified various traces of matching tactics, techniques, and procedures (TTPs) used by Team TNT in its 2023 and 2024 campaigns.

Motivations
Financial gain, beginning with SSH brute-force attacks and malicious script uploads.
Top 10 Masked Actors for 2025
RansomHub
#1
GoldFactory
#2
Lazarus
#3
DragonForce
#4
Oilrig
#5
MuddyWater
#6
Brain Cipher
#7
Boolka
#8
Ajina
#9
Team TNT
#10