Watchdog (Thief Libra) is an opportunistic cloud threat group known for cryptojacking and credential scraping.
Analyst brief
Watchdog, also known as Thief Libra, is an opportunistic cloud-focused threat group involved in cryptojacking and cloud service credential scraping. They target exposed cloud instances and applications, leveraging custom-built Go scripts and repurposed cryptojacking tools from groups like TeamTNT. Defenders should prioritize identifying misconfigured cloud resources, monitoring for unauthorized credential access, and detecting suspicious Go script executions.
Watchdog
Thief Libra
unknown
Thief Libra is a cloud-focused threat group that has a history of cryptojacking operations as well as cloud service platform credential scraping. They were first known to operate on January 27, 2019. They use a variety of custom build Go Scripts as well as repurposed cryptojacking scripts from other groups including TeamTNT. They are currently considered to be an opportunistic threat group that targets exposed cloud instances and applications.