律动BlockBeats|Sep 22, 2026 03:57
**[North Korea-Linked Hacker Group TraderTraitor Launches New Wave of Attacks Using Malicious Terraform Projects]**
BlockBeats News, September 22: According to disclosures by SlowMist, the North Korea-linked threat group TraderTraitor (also known as UNC4899, Jade Sleet) has launched another attack, recently infiltrating an IT service company in India that is unrelated to the crypto industry. The attackers posted fake job listings on GitHub, using "technical interview assignments" as bait to target DevOps and crypto engineers with phishing attacks.
Once victims download the related project, the malicious `.terraform.lock.hcl` file directs to a Terraform Provider domain controlled by the attackers. Running `terraform init` triggers the download and execution of the malicious Provider module. Ultimately, the attack deploys Rust/ARM64 backdoors FLATROOF and ROOFDECK on the victim's macOS devices. These malware families were previously used in LayerZero attacks and are capable of stealing credentials and sensitive data, executing shell commands, collecting and exfiltrating files, and gaining access to cloud services and code repositories.
SlowMist warns that TraderTraitor's attack targets are no longer limited to the crypto industry; the attackers may be more focused on developers' access to cloud platforms and APIs such as AWS, GCP, OVH, and OpenStack. Companies should exercise caution when handling unfamiliar Terraform Providers and code repositories provided by recruiters, and avoid using personal or corporate development devices to execute unverified interview projects.
[Original Link]
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink