* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Monday, December 22, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    Concert venue, entertainment district planned for downtown Tampa – Spectrum Bay News 9

    Downtown Tampa to Unveil Thrilling New Concert Venue and Entertainment District

    $150 million, 12,500-seat entertainment venue coming to Houston in 2027 – CultureMap Houston

    Houston Set to Unveil a Spectacular $150 Million, 12,500-Seat Entertainment Venue in 2027

    WildBrain Sells Stake in Peanuts Holdings to Sony Pictures Entertainment – Licensing International

    WildBrain Sells Stake in Peanuts Holdings to Sony Pictures Entertainment – Licensing International

    Country music star, wife are getting divorced: ‘We are no longer suited to be married’ – PennLive.com

    Country Music Star and Spouse Reveal They Are No Longer Suited for Marriage

    Nate Bargatze is leaving his podcast — and Utah recently saw why – Deseret News

    Nate Bargatze Is Leaving His Podcast – What Utah Fans Recently Went Through

    State Farm Arena Ranks In The Top 5 Live Entertainment Venues In The U.S. & Top 7 In The World, According To Billboard – Secret Atlanta

    State Farm Arena Ranks In The Top 5 Live Entertainment Venues In The U.S. & Top 7 In The World, According To Billboard – Secret Atlanta

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Technology Stocks Week Ahead: AI Spending Scrutiny, Fed Rate Path, and Holiday-Thin Trading to Drive Tech Stocks (Dec. 22–26, 2025) – ts2.tech

    Tech Stocks Outlook for Dec. 22-26, 2025: AI Investments, Fed Rate Moves, and Holiday-Thin Trading to Drive Market Action

    Technology is powerful but unforgiving when misused – Supreme Court judge warns – GhanaWeb

    Supreme Court Judge Issues Stark Warning: Technology’s Power Can Be Dangerous When Misused

    The 8 worst technology flops of 2025 – MIT Technology Review

    The 8 worst technology flops of 2025 – MIT Technology Review

    Bangor School District receives new CNC router technology from First National Bank – news8000.com

    Bangor School District Unveils Cutting-Edge CNC Router Technology Thanks to Local Support

    6G discussions: How things have changed – 5gtechnologyworld.com

    The Evolution of 6G: How the Conversation Has Transformed

    Retail supply chains brace for a redefined 2026 as tariffs, technology gaps, and nearshoring upend old models – Raleigh News & Observer

    Retail Supply Chains Revolutionize in 2026: How Tariffs, Technology Gaps, and Nearshoring Are Shaping the Future

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    Concert venue, entertainment district planned for downtown Tampa – Spectrum Bay News 9

    Downtown Tampa to Unveil Thrilling New Concert Venue and Entertainment District

    $150 million, 12,500-seat entertainment venue coming to Houston in 2027 – CultureMap Houston

    Houston Set to Unveil a Spectacular $150 Million, 12,500-Seat Entertainment Venue in 2027

    WildBrain Sells Stake in Peanuts Holdings to Sony Pictures Entertainment – Licensing International

    WildBrain Sells Stake in Peanuts Holdings to Sony Pictures Entertainment – Licensing International

    Country music star, wife are getting divorced: ‘We are no longer suited to be married’ – PennLive.com

    Country Music Star and Spouse Reveal They Are No Longer Suited for Marriage

    Nate Bargatze is leaving his podcast — and Utah recently saw why – Deseret News

    Nate Bargatze Is Leaving His Podcast – What Utah Fans Recently Went Through

    State Farm Arena Ranks In The Top 5 Live Entertainment Venues In The U.S. & Top 7 In The World, According To Billboard – Secret Atlanta

    State Farm Arena Ranks In The Top 5 Live Entertainment Venues In The U.S. & Top 7 In The World, According To Billboard – Secret Atlanta

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Technology Stocks Week Ahead: AI Spending Scrutiny, Fed Rate Path, and Holiday-Thin Trading to Drive Tech Stocks (Dec. 22–26, 2025) – ts2.tech

    Tech Stocks Outlook for Dec. 22-26, 2025: AI Investments, Fed Rate Moves, and Holiday-Thin Trading to Drive Market Action

    Technology is powerful but unforgiving when misused – Supreme Court judge warns – GhanaWeb

    Supreme Court Judge Issues Stark Warning: Technology’s Power Can Be Dangerous When Misused

    The 8 worst technology flops of 2025 – MIT Technology Review

    The 8 worst technology flops of 2025 – MIT Technology Review

    Bangor School District receives new CNC router technology from First National Bank – news8000.com

    Bangor School District Unveils Cutting-Edge CNC Router Technology Thanks to Local Support

    6G discussions: How things have changed – 5gtechnologyworld.com

    The Evolution of 6G: How the Conversation Has Transformed

    Retail supply chains brace for a redefined 2026 as tariffs, technology gaps, and nearshoring upend old models – Raleigh News & Observer

    Retail Supply Chains Revolutionize in 2026: How Tariffs, Technology Gaps, and Nearshoring Are Shaping the Future

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Infosec watchers: TeamTNT crew may blast holes in Azure, Google Cloud users

July 15, 2023
in Technology
Infosec watchers: TeamTNT crew may blast holes in Azure, Google Cloud users
Share on FacebookShare on Twitter

A criminal crew with a history of deploying malware to harvest credentials from Amazon Web Services accounts may expand its attention to organizations using Microsoft Azure and Google Cloud Platform.

Researchers with SentinelOne, Permiso Security, and Aqua Security say a credential-stealing campaign, which began in June, includes the hallmarks of the notorious TeamTNT, though full attribution is difficult.

That said, given the amount of work the miscreants have done to improve their techniques and the addition of Azure and Google Cloud accounts to the list of targets, the group looks set to ramp up its attacks, according to Alex Delamotte, researcher with SentinelOne’s SentinelLabs unit.

Whoever the miscreants are, it appears they scrape cloud infrastructure credentials – such as AWS keys – from victims’ Jupyter programming notebooks; accessing those notebooks may require the exploitation of poorly secured web applications, or the notebooks may have been accidentally left open to the public, it seems. The crooks’ ultimate goal is to get credentials, use them to copy malware onto someone else’s cloud-based systems, and run that malware.

Once the crew’s code is executing on a victim’s resources, the intruders can run scripts on those remote systems that search for and harvest more access credentials, mine cryptocurrencies, open a backdoor, and potentially siphon off information or meddle with operations. The crooks used to target primarily AWS users, and now seem to be looking for ways into Azure and Google Cloud accounts.

“While AWS has long been in the crosshairs of many cloud-focused actors, the expansion to Azure and GCP credentials indicates there are other major contenders holding valuable data,” Delamotte wrote in a report this week.

“We believe this actor is actively tuning and improving their tools. Based on the tweaks observed across the past several weeks, the actor is likely preparing for larger scale campaigns.”

Permiso researcher Abian Morina reckoned on Wednesday a multi-cloud campaign may already be underway as of this week.

It is not entirely clear exactly how the miscreants break into people’s cloud resources: check the linked advisories for technical details and indicators of compromise, and use the given info to detect and stop any identifiable intrusions, we say.

Cloud credentials are a popular target

According a write-up last year from Elastic Security Labs, 33 percent of cyberattacks in the cloud use stolen credentials, something TeamTNT is known for. The group has been around since 2019, though two years ago it announced it was quitting. However Trend Micro said the crew, known for targeting cloud and container environments, was back in business as of late last year.

Permiso in December 2022 documented how TeamTNT was scouring Jupyter Notebook services primarily for AWS credentials. The miscreants appear to have started targeting vulnerable Docker deployments, too, and updated their intrusion tools.

Those updates have brought in support for obtaining Azure and Google Cloud credentials, made the scripts more modular to achieve more complex attacks, improved the credential harvesting, and brought in the curl command-line tool to exfiltrate data.

AT&T Alien Labs warns of ‘zero or low detection’ for TeamTNT’s latest malware bundle

FBI: BlackCat ransomware scratched 60-plus orgs

Microsoft defends intrusive dialog in Visual Studio Code that asks if you really trust the code you’ve been working on

Microsoft stole our stolen dark web data, says security outfit

In addition, the group previously hosted its command-and-control (C2) activities and files in an openly accessible directory on a single domain. Now the C2’s directory requires a hardcoded username and password to access, making it tougher to inspect and stop. This infrastructure, which previously used a Netherlands-based IP address, now runs across several subdomains.

The researchers also found an ELF binary built from Golang source code; this executable is used to spread the malware to other vulnerable targets, seemingly in a worm-like fashion. The miscreants hide this system scanner as an embedded base64 object within the binary to make it more difficult to detect.

Something wicked this way comes

The latest campaign “demonstrates the evolution of a seasoned cloud actor with familiarity across many technologies,” Delamotte wrote.

“The meticulous attention to detail indicates the actor has clearly experienced plenty of trial and error. The actor has also improved the tool’s data formatting to enable more autonomous activity, which demonstrates a certain level of maturity and skill.”

The work SentinelLabs and Permiso echoes what Aqua uncovered earlier this month in connection with a “potentially massive campaign against cloud native environments” that researchers Ofek Itach and Assaf Morag laid at the feet of TeamTNT or a group using the same techniques.

Their investigation kicked off after an attack was detected against a Jupyter honeypot run by Aqua, and led to an examination of a container image and Docker Hub account, they wrote. They described the Silentbob campaign as an “aggressive cloud worm, designed to deploy on exposed JupyterLab and Docker APIs in order to deploy Tsunami malware, cloud credentials hijack, resource hijack and further infestation of the worm.”

Like SentinelLabs, the Aqua researchers said it appeared that what they were looking at was a trial run for a bigger operation.

“Given that some functions in the code remain unused and the linked attack patterns suggest manual testing, we theorize that the attacker is in the process of optimizing their algorithm,” they wrote at the start of July.

“Looks like TeamTNT or a TeamTNT copycat is preparing a campaign. We treat this as an early warning, and hopefully a prevention to the campaign.”

Aqua and SentinelLabs recommended enterprises protect themselves against such attacks by taking such steps as not deploying Jupyter software without authentication, properly configuring and patching web applications to minimize exploitation, restricting external access to Docker, and using the least-privilege principle by limiting the permissions of containers. ®

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : The Register – https://go.theregister.com/feed/www.theregister.com/2023/07/15/teamtnt_aws_azure_google/

Tags: infosectechnologywatchers
Previous Post

Now Foxconn hopes to lure TSMC, Japan’s TMH into India chip fab pact – report

Next Post

Tesla Cybertruck bidirectional charging hint found in Tesla colouring book of all places

Real-World Agent Examples with Gemini 3 – blog.google

Discover Real-World Agent Examples with Gemini 3

December 22, 2025
Both major political parties have seized on the economy as we approach mid-term elections in 2026. How are you feeling about the economy? – The Frederick News-Post

With Midterm Elections Approaching, Both Parties Clash Over the Economy – What’s Your Take?

December 22, 2025
Concert venue, entertainment district planned for downtown Tampa – Spectrum Bay News 9

Downtown Tampa to Unveil Thrilling New Concert Venue and Entertainment District

December 22, 2025
Rep. Moulton goes ‘On the Record’ about US Senate race, health care – WCVB

Rep. Moulton Shares Candid Insights on the Senate Race and Tackling Health Care Challenges

December 22, 2025
Friday letters: Reading, giving, politics, civic engagement and more – Post Independent

Friday letters: Reading, giving, politics, civic engagement and more – Post Independent

December 22, 2025
Stage-specific microbial dynamics underpin ecosystem restoration on tropical coral islands – EurekAlert!

Stage-specific microbial dynamics underpin ecosystem restoration on tropical coral islands – EurekAlert!

December 22, 2025
Threatening NCAR, Trump administration seeks to extinguish a beacon of climate science – Bulletin of the Atomic Scientists

Trump Administration Takes Aim at a Leading Voice in Climate Science

December 22, 2025
Ancient oceans were ruled by super predators unlike anything today – ScienceDaily

Ancient Oceans Were Home to Incredible Super Predators Unlike Anything Alive Today

December 22, 2025
A Lifestyle Rx For Keeping Your Brain Young – Indiana Gazette Online

Unlock the Secret to a Youthful, Sharp Brain with This Lifestyle Rx

December 21, 2025
Technology Stocks Week Ahead: AI Spending Scrutiny, Fed Rate Path, and Holiday-Thin Trading to Drive Tech Stocks (Dec. 22–26, 2025) – ts2.tech

Tech Stocks Outlook for Dec. 22-26, 2025: AI Investments, Fed Rate Moves, and Holiday-Thin Trading to Drive Market Action

December 21, 2025

Categories

Archives

December 2025
M T W T F S S
1234567
891011121314
15161718192021
22232425262728
293031  
« Nov    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (981)
  • Economy (1,000)
  • Entertainment (21,877)
  • General (18,881)
  • Health (10,040)
  • Lifestyle (1,012)
  • News (22,149)
  • People (1,006)
  • Politics (1,014)
  • Science (16,215)
  • Sports (21,500)
  • Technology (15,982)
  • World (989)

Recent News

Real-World Agent Examples with Gemini 3 – blog.google

Discover Real-World Agent Examples with Gemini 3

December 22, 2025
Both major political parties have seized on the economy as we approach mid-term elections in 2026. How are you feeling about the economy? – The Frederick News-Post

With Midterm Elections Approaching, Both Parties Clash Over the Economy – What’s Your Take?

December 22, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version