Hacking

TeamTNT Resurfaces, Targeting CentOS VPS in Cryptojacking Campaign

Published  ·  2 min read

The infamous cryptojacking group TeamTNT has likely resurfaced, launching a new campaign aimed at Virtual Private Server (VPS) infrastructures running the CentOS operating system, according to researchers at Group-IB.

The attack starts with a Secure Shell (SSH) brute force attack on the victim’s systems, followed by the upload of a malicious script. This script, as noted by Group-IB researchers Vito Alfano and Nam Le Phuong, disables critical security features, deletes logs, terminates existing cryptocurrency mining processes, and hinders recovery efforts.

In this attack chain, the Diamorphine rootkit is deployed to conceal malicious activities, while also setting up persistent remote access to the compromised host. Group-IB attributed the campaign to TeamTNT with moderate confidence, pointing out the similarities in the tactics, techniques, and procedures (TTPs) employed.

TeamTNT was originally discovered in 2019, focusing on illicit cryptocurrency mining by infiltrating cloud and container environments. The group had seemingly disbanded in November 2021, but multiple campaigns linked to them have been identified since September 2022.

In the latest campaign, the attackers use a shell script that checks for existing infections by other cryptojacking operations, then proceeds to disable SELinux, AppArmor, and the firewall to weaken the server’s security.

Changes to SSH and Cloud Services:

The script also specifically targets Alibaba Cloud by searching for a daemon related to the cloud provider called aliyun.service. If detected, it downloads and executes a bash script from update.aegis.aliyun.com to uninstall the service.

In addition to terminating competing cryptocurrency mining processes, the script executes a series of commands designed to eliminate traces of other miners, shut down containerized processes, and remove mining-related images.

To establish persistence, the script configures cron jobs that download the malicious shell script every 30 minutes from a remote server (65.108.48[.]150) and modifies the "/root/.ssh/authorized_keys" file to add a backdoor account.

The attackers also implement various changes within the SSH and firewall service configurations, lock down the system by modifying file attributes, create a backdoor user with root access, and erase the command history to hide their tracks.

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067