AT&T Alien Labs security researchers discovered that TeamTNT upgraded Linux crypto-mining with open source detection evasion capabilities.
TeamTNT is primarily known for targeting and hacking “docker instances” running on the internet for unauthorized mining of the Monero (XMR) cryptocurrency.
However, the group has also changed tactics by updating its cryptojacking malware called Black-T to also collect user credentials from infected servers.

TeamTNT further upgraded the malware to evade detection after infecting and deploying malicious coinminer payloads on Linux devices.
“The group uses a new evasion tool, copied from open source repositories,” says security researcher Ofer Caspi in a report published today.
This tool is known as libprocesshider and is an open source tool available on Github, which can be used to hide any Linux process with the help of ld preloader.
"The goal of the new tool is to hide the malicious process from process information programs like 'ps' and 'lsof'," Caspi added.
The evasion detection tool is deployed to infected systems as a base64 encoded bash script embedded within the TeamTNT ircbot or cryptominer binary.
Once the script is “installed” on a compromised computer , it will perform a series of tasks that will allow it to:
- Modify the network DNS configuration.
- Configure persistence via systemd.
- Activate the new tool as a service.
- Download the latest IRC bot configuration.
- Clear clear indications of activities that complicate potential defensive actions.
After all the steps, the Black-T malware will delete all traces of malicious activity by deleting the system's bash history.
Information source: bleepingcomputer.com
