Home / Companies / Sysdig / Blog / Post Details
Content Deep Dive

Threat news: TeamTNT targeting misconfigured kubelet

Blog post from Sysdig

Post Details
Company
Date Published
Author
Alberto Pellitteri
Word Count
1,594
Company Posts That Month
15
Language
English
Hacker News Points
-
Post removed?
No
Summary

TeamTNT, a well-known threat actor group, has been targeting cloud and virtual environments like Kubernetes and Docker since 2019, focusing on credential theft and cryptomining. In a recent campaign, they exploited a misconfigured kubelet service in Kubernetes clusters to access pods, download malicious binaries, and execute scripts aimed at stealing AWS credentials and other sensitive data. The attack involved downloading and executing a series of scripts that searched for various credentials, exfiltrating them to TeamTNT's command and control servers. The group is also expanding its focus beyond AWS to other platforms, including GitHub and SSH keys. To mitigate such threats, it is recommended to avoid exposing kubelet services to public networks with anonymous access and to secure credentials properly. Falco, a CNCF incubating project, can help detect these malicious activities in real time by using customizable rules to monitor for anomalies in cloud-native environments.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Kubernetes 8 1,195 149 62 +21%
Secrets Management 3 356 70 42 -31%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.