A malicious actor has been linked to a cloud credential stealing campaign in June 2023 that’s focused on Azure and Google Cloud Platform (GCP) services, marking the adversary’s expansion in targeting beyond Amazon Web Services (AWS).
The findings come from SentinelOne and Permiso, which said the “campaigns share similarity with tools attributed to the notorious TeamTNT cryptojacking crew,”