律动BlockBeats
律动BlockBeats|Sep 22, 2026 03:57
**[North Korea-Linked Hacker Group TraderTraitor Launches New Wave of Attacks Using Malicious Terraform Projects]** BlockBeats News, September 22: According to disclosures by SlowMist, the North Korea-linked threat group TraderTraitor (also known as UNC4899, Jade Sleet) has launched another attack, recently infiltrating an IT service company in India that is unrelated to the crypto industry. The attackers posted fake job listings on GitHub, using "technical interview assignments" as bait to target DevOps and crypto engineers with phishing attacks. Once victims download the related project, the malicious `.terraform.lock.hcl` file directs to a Terraform Provider domain controlled by the attackers. Running `terraform init` triggers the download and execution of the malicious Provider module. Ultimately, the attack deploys Rust/ARM64 backdoors FLATROOF and ROOFDECK on the victim's macOS devices. These malware families were previously used in LayerZero attacks and are capable of stealing credentials and sensitive data, executing shell commands, collecting and exfiltrating files, and gaining access to cloud services and code repositories. SlowMist warns that TraderTraitor's attack targets are no longer limited to the crypto industry; the attackers may be more focused on developers' access to cloud platforms and APIs such as AWS, GCP, OVH, and OpenStack. Companies should exercise caution when handling unfamiliar Terraform Providers and code repositories provided by recruiters, and avoid using personal or corporate development devices to execute unverified interview projects. [Original Link]
+1
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads