GBHackers

Suspected TraderTraitor Hackers Trojanize Terraform Provider to Deploy Cross-Platform Malware


A campaign in July 2026 using a trojanized Terraform provider to deploy cross-platform malware against developer environments.

The operation delivers FLATROOF for credential theft and initial access, followed by ROOFDECK for broader remote control.

Attribution remains provisional. ThreatLabz found similarities in targeting, tooling, and tactics but lacked unique code matches, shared infrastructure, or cryptographic evidence sufficient for independent, high-confidence attribution.

The initial delivery mechanism for the analyzed provider also remains unresolved.

The Go binary, terraform-provider-awsbeta_v1.0.0, impersonates an AWS Terraform provider while retaining a functional provider scaffold.

Attackers inserted a malicious awsbeta package and invoked it directly from main, triggering execution when Terraform starts the plugin.

The implant checks for session.lock in the temporary directory before downloading a Bash loader from hashicorp-terraform[.]io.

It saves the script as safari_updater, grants execution permissions, launches a detached process, and creates the marker to suppress repeat execution. Normal provider behavior continues, reducing visible disruption.

The loader identifies the operating system and processor architecture, then selects an encrypted payload disguised as a .woff font.

Infection chain delivering FLATROOF and ROOFDECK through a trojanized Terraform provider (Source : Zscaler).

Zscaler ThreatLabz said in a report shared with GBhackers, significant overlap with TraderTraitor, a North Korean state-backed actor tracked as Jade Sleet, UNC4899, Pressure Chollima, and Slow Pisces.

Terraform Supply Chain

Linux, macOS, and Windows use NotoSansCJK, HiraginoSans, and MalgunGothic filenames respectively; Windows execution requires a compatible Unix-like shell environment.

The first is a 64-bit Windows executable that is decoded using the XOR key 0x37 and injected into a suspended Chromium process to recover master encryption keys.

Downloads fall back across dynamic DNS infrastructure, GitHub, and Vercel. Each file combines decoy font content with an @@ENDFONT@@ marker and encrypted executable.


Python script showing indications of code generated using AI (Source : Zscaler).
 Python script showing indications of code generated using AI (Source : Zscaler).

The loader extracts the appended content, Base64-decodes it, and applies AES-256-CBC decryption through available Python, Node.js, Perl, or OpenSSL tooling.

On macOS, it removes the quarantine attribute and applies an ad hoc signature before execution.

The Rust-based FLATROOF backdoor decrypts its configuration using PBKDF2-HMAC-SHA256 and AES-256-GCM.

Its code supports Telegram, GitHub API polling, and attacker-controlled HTTP webhooks, although individual samples do not necessarily configure every channel.

Persistence varies by platform: Linux services, macOS shell logout mechanisms, and Windows registry Run values.

Embedded Python collectors harvest browser databases, cookies, saved credential artifacts, terminal histories, application inventories, and host information.

Platform-specific collection includes Linux keyrings, macOS login.keychain-db, and Windows Credential Manager entries. Windows scripts additionally target MetaMask, Phantom, Trust Wallet, and Rabby extension data.

An embedded native component executes inside a suspended Chromium process to recover browser encryption keys.

Attacker-controlled Nostr profile and metadata used to locate the current Pastebin URL for C2 discovery (Source : Zscaler).
Attacker-controlled Nostr profile and metadata used to locate the current Pastebin URL for C2 discovery (Source : Zscaler).

ROOFDECK resolves its command-and-control address through local configuration, a signed and encrypted Pastebin dead drop, or Nostr profile metadata.

RSA signature verification prevents unauthorized replacement of the accepted server address. Nostr’s profile website field can redirect the implant to the current Pastebin location.

Once connected over HTTP or WebSocket endpoints, ROOFDECK supports reconnaissance, interactive shells, file transfers, clipboard access, persistence management, and self-removal.

The malware overlaps with the KelpDAO incident report, which documented developer compromise preceding the $292 million bridge theft.

SentinelLabs’ related investigation also identified an Indian IT-services victim without cryptocurrency ties. Earlier Unit 42 research documented recruiter impersonation and malicious coding challenges targeting developers.

Organizations should restrict untrusted providers, verify checksums against trusted sources, inspect supplied lockfiles, and monitor unexpected provider-spawned processes.

SentinelLabs recommends scrutinizing unfamiliar registries and separating external interview assignments from corporate workstations, particularly where engineers hold cloud credentials or source-control access.

Indicators Of Compromise

IndicatorFile nameDescription
9d78ece09457907b730d139e4e0c64dd terraform-provider-awsbeta_v1.0.0Trojanized Terraform provider
73adaea97f003735335505858c1c6def safari_updaterBash script
116f7189ed7b41f1b339a749d56e63beHiraginoSans-Bold.woffEncrypted Mach-O 64-bit x86_64 FLATROOF
be60c52ca8a01fef7dc15c2f0ebb77d8HiraginoSans-Regular.woffEncrypted Mach-O 64-bit arm64 FLATROOF
58fa0d651898446d5f5d2ed8a27a3330MalgunGothic-Bold.woffEncrypted PE32+ FLATROOF

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.



Source link