Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0139
MITRE ATT&CK Group

TeamTNT (G0139)

ShareXLinkedInRedditHN

[TeamTNT](https://attack.mitre.org/groups/G0139) is a threat group that has primarily targeted cloud and containerized environments. The group as been active since at least October 2019 and has mainly focused its efforts on leveraging cloud and container resources to deploy cryptocurrency miners in victim environments.(Citation: Palo Alto Black-T October 2020)(Citation: Lacework TeamTNT May 2021)(Citation: Intezer TeamTNT September 2020)(Citation: Cado Security TeamTNT Worm August 2020)(Citation: Unit 42 Hildegard Malware)(Citation: Trend Micro TeamTNT)(Citation: ATT TeamTNT Chimaera September 2020)(Citation: Aqua TeamTNT August 2020)(Citation: Intezer TeamTNT Explosion September 2021)

▪Techniques used (56)

T1680Local Storage DiscoveryT1686Disable or Modify System FirewallT1133External Remote ServicesT1219Remote Access ToolsT1569.003SystemctlT1036.005Match Legitimate Resource Name or LocationT1222.002Linux and Mac PermissionsT1070.004File DeletionT1609Container Administration CommandT1059.004Unix ShellT1547.001Registry Run Keys / Startup FolderT1543.002Systemd ServiceT1136.001Local AccountT1007System Service DiscoveryT1049System Network Connections DiscoveryT1543.003Windows ServiceT1608.001Upload MalwareT1059.003Windows Command ShellT1610Deploy ContainerT1613Container and Resource DiscoveryT1048Exfiltration Over Alternative ProtocolT1057Process DiscoveryT1059.001PowerShellT1552.005Cloud Instance Metadata APIT1070.003Clear Command HistoryT1074.001Local Data StagingT1595.002Vulnerability ScanningT1059.013Container CLI/APIT1027.002Software PackingT1204.003Malicious ImageT1014RootkitT1552.004Private KeysT1611Escape to HostT1595.001Scanning IP BlocksT1105Ingress Tool TransferT1518.001Security Software DiscoveryT1496.001Compute HijackingT1083File and Directory DiscoveryT1021.004SSHT1036MasqueradingT1140Deobfuscate/Decode Files or InformationT1082System Information DiscoveryT1027.013Encrypted/Encoded FileT1016System Network Configuration DiscoveryT1046Network Service DiscoveryT1120Peripheral Device DiscoveryT1685Disable or Modify ToolsT1071Application Layer ProtocolT1098.004SSH Authorized KeysT1583.001DomainsT1059.009Cloud APIT1071.001Web ProtocolsT1552.001Credentials In FilesT1685.006Clear Linux or Mac System LogsT1587.001MalwareT1102Web Service

▪Software used (4)

S0683PeiratestoolS0179MimiPenguintoolS0349LaZagnetoolS0601Hildegardmalware
G0139on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.