SlowMist|Sep 22, 2026 03:55
🚨SlowMist TI Alert: TraderTraitor Resurfaces via Weaponized Terraform Projects🚨
DPRK-aligned threat actor #TraderTraitor (aka UNC4899, Jade Sleet) — previously behind the April 2026 LayerZero/KelpDAO breach (~$292M stolen) has compromised a new victim: an India-based IT services company with no ties to crypto.
⚠️ Attack chain:
🎯 Fake job interview lures target DevOps/crypto engineers on GitHub
📦 Weaponized .terraform.lock.hcl files point to attacker-controlled Terraform provider domains
⚙️ Running terraform init triggers download & execution of malicious provider modules
💻 Deploys two macOS backdoors (Rust/ARM64): FLATROOF & ROOFDECK — same families used in the LayerZero attack
🔑 Capabilities include:
• Credential and sensitive data theft
• Shell and command execution
• File collection and exfiltration
• Cloud and source-control access
📌 This shows TraderTraitor is casting a wider net — even orgs with zero crypto exposure are being targeted, likely for whatever cloud/API access their developers can reach (AWS, GCP, OVH, OpenStack).
🛡️ Recommendations:
👉 Treat unknown Terraform provider registries as suspect — verify against http://registry.terraform.io.
👉 Flag engineers with cloud/source-control access for enhanced endpoint monitoring.
👉 Be wary of unsolicited coding "interview assignments" and repos from recruiters.
👉 Avoid using personal/corporate dev workstations for external job interviews.
🔎 Source: @LabsSentinel
https://www.sentinelone.com/labs/dont-call-us-well-call-your-apis-tradertraitor-backdoors-resurface-on-victim-with-no-crypto-ties/
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink