TeamTNT is reportedly keeping an eye on the credentials of AWS, Google Cloud

[ad_1]

Application security, fraud management and cybercrime, ID identity fraud

Group uses compromised credentials to attack cloud providers, say researchers Rashmi Ramesh • June 11, 2021 Compromised AWS credentials used to attack cloud environments (Image Source: Shutterstock)

Cryptojacking group TeamTNT is leveraging Amazon Web Services ‘compromised credentials to attack its cloud environments via the platforms’ application programming interface, according to a report from Unit 42 of Palo Alto Networks.

See also: Live Webinar | The role of passwords in the hybrid workforce

TeamTNT’s operations targeted and, after compromise, exfiltrated AWS credentials, targeted Kubernetes clusters, and created new malware called Black-T which integrates open source cloud-native tools to assist in their cryptojacking operations. the report states. Kubernetes is a container orchestration platform developed and supported by Google.

The cybercriminal gang is attempting to identify all identity and access management permissions, Elastic Compute Cloud instances, Simple Storage Service buckets, CloudTrail configurations, and CloudFormation operations granted to compromised AWS credentials, it says the report.

An AWS spokesperson told Information Security Media Group that the reported activity was not a vulnerability on AWS. The company lists AWS security best practices and IAM security best practices to help users protect their credentials.

Other targeted cloud-based apps

The cybercriminal organization, which developed its cloud-centric cryptojacking operations, is also targeting the credentials of 16 other cloud-based applications, including Google Cloud, Docker, GitHub, Shodan, Ngrok, Pidgin, Filezilla, HexChat and Project Jupyter.

Its focus on Google Cloud marks the first known instance of a group of attackers targeting IAM credentials on compromised cloud instances outside of AWS, the Palo Alto report states.

Google Cloud did not respond to ISMG’s request for comment.

Additionally, TeamTNT has added the use of open source Kubernetes and the Peirates cloud penetration toolset to its reconnaissance operations, the Palo Alto report states.

With these techniques available, TeamTNT actors are increasingly able to gather enough information in the target AWS and Google Cloud environments to perform further post-exploitation operations. This could lead to more cases of lateral movement and potential privilege escalation attacks that could ultimately allow TeamTNT actors to gain administrative access to an entire organization’s cloud environment, the report said.

Other exploits

Although the credentials of Microsoft Azure, Alibaba Cloud, Oracle Cloud and IBM Cloud IAM may have been targeted using similar methods, the Palo Alto researchers say they have not yet found evidence to support such a proposal.

Separately, the researchers identified one of TeamTNT’s malware repositories, which contains several bash scripts designed to perform cryptojacking, exploitation, side-shifting, and credential scraping operations. Dubbed Chimaera, the malware repository highlights the expanding scope of TeamTNT’s operations within cloud environments and a set goal for current and future operations.

In a recent report, Trend Micro claims that the threat actor searched for and compromised Kubernetes clusters in the wild.

The report says it compromised more than 50,000 IPs across multiple clusters between March and May, targeting internet and cloud service providers in several countries, with a focus on China and the United States.

Defense and prevention

TeamTNT actors are specifically targeting cloud platforms to bypass future security detection tools and integrate into organizations’ cloud environment, the Palo Alto report states.

We recommend organizations working with cloud environments to monitor and block all network connections associated with TeamTNT’s Chimaera repository, as well as historical Command and Control (C2) endpoints. Using a cloud-native security platform will significantly reduce the attack surface of cloud infrastructures and enable organizations to monitor risks, the report said.

[ad_2]

picture credit

Related Posts