SlowMist
SlowMist|Sep 22, 2026 03:55
🚨SlowMist TI Alert: TraderTraitor Resurfaces via Weaponized Terraform Projects🚨 DPRK-aligned threat actor #TraderTraitor (aka UNC4899, Jade Sleet) — previously behind the April 2026 LayerZero/KelpDAO breach (~$292M stolen) has compromised a new victim: an India-based IT services company with no ties to crypto. ⚠️ Attack chain: 🎯 Fake job interview lures target DevOps/crypto engineers on GitHub 📦 Weaponized .terraform.lock.hcl files point to attacker-controlled Terraform provider domains ⚙️ Running terraform init triggers download & execution of malicious provider modules 💻 Deploys two macOS backdoors (Rust/ARM64): FLATROOF & ROOFDECK — same families used in the LayerZero attack 🔑 Capabilities include: • Credential and sensitive data theft • Shell and command execution • File collection and exfiltration • Cloud and source-control access 📌 This shows TraderTraitor is casting a wider net — even orgs with zero crypto exposure are being targeted, likely for whatever cloud/API access their developers can reach (AWS, GCP, OVH, OpenStack). 🛡️ Recommendations: 👉 Treat unknown Terraform provider registries as suspect — verify against http://registry.terraform.io. 👉 Flag engineers with cloud/source-control access for enhanced endpoint monitoring. 👉 Be wary of unsolicited coding "interview assignments" and repos from recruiters. 👉 Avoid using personal/corporate dev workstations for external job interviews. 🔎 Source: @LabsSentinel https://www.sentinelone.com/labs/dont-call-us-well-call-your-apis-tradertraitor-backdoors-resurface-on-victim-with-no-crypto-ties/
+2
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads