A campaign in July 2026 using a trojanized Terraform provider to deploy cross-platform malware against developer environments.
The operation delivers FLATROOF for credential theft and initial access, followed by ROOFDECK for broader remote control.
Attribution remains provisional. ThreatLabz found similarities in targeting, tooling, and tactics but lacked unique code matches, shared infrastructure, or cryptographic evidence sufficient for independent, high-confidence attribution.
The initial delivery mechanism for the analyzed provider also remains unresolved.
The Go binary, terraform-provider-awsbeta_v1.0.0, impersonates an AWS Terraform provider while retaining a functional provider scaffold.
Attackers inserted a malicious awsbeta package and invoked it directly from main, triggering execution when Terraform starts the plugin.
The implant checks for session.lock in the temporary directory before downloading a Bash loader from hashicorp-terraform[.]io.
It saves the script as safari_updater, grants execution permissions, launches a detached process, and creates the marker to suppress repeat execution. Normal provider behavior continues, reducing visible disruption.
The loader identifies the operating system and processor architecture, then selects an encrypted payload disguised as a .woff font.
Zscaler ThreatLabz said in a report shared with GBhackers, significant overlap with TraderTraitor, a North Korean state-backed actor tracked as Jade Sleet, UNC4899, Pressure Chollima, and Slow Pisces.
Terraform Supply Chain
Linux, macOS, and Windows use NotoSansCJK, HiraginoSans, and MalgunGothic filenames respectively; Windows execution requires a compatible Unix-like shell environment.
The first is a 64-bit Windows executable that is decoded using the XOR key 0x37 and injected into a suspended Chromium process to recover master encryption keys.
Downloads fall back across dynamic DNS infrastructure, GitHub, and Vercel. Each file combines decoy font content with an @@ENDFONT@@ marker and encrypted executable.

The loader extracts the appended content, Base64-decodes it, and applies AES-256-CBC decryption through available Python, Node.js, Perl, or OpenSSL tooling.
On macOS, it removes the quarantine attribute and applies an ad hoc signature before execution.
The Rust-based FLATROOF backdoor decrypts its configuration using PBKDF2-HMAC-SHA256 and AES-256-GCM.
Its code supports Telegram, GitHub API polling, and attacker-controlled HTTP webhooks, although individual samples do not necessarily configure every channel.
Persistence varies by platform: Linux services, macOS shell logout mechanisms, and Windows registry Run values.
Embedded Python collectors harvest browser databases, cookies, saved credential artifacts, terminal histories, application inventories, and host information.
Platform-specific collection includes Linux keyrings, macOS login.keychain-db, and Windows Credential Manager entries. Windows scripts additionally target MetaMask, Phantom, Trust Wallet, and Rabby extension data.
An embedded native component executes inside a suspended Chromium process to recover browser encryption keys.

ROOFDECK resolves its command-and-control address through local configuration, a signed and encrypted Pastebin dead drop, or Nostr profile metadata.
RSA signature verification prevents unauthorized replacement of the accepted server address. Nostr’s profile website field can redirect the implant to the current Pastebin location.
Once connected over HTTP or WebSocket endpoints, ROOFDECK supports reconnaissance, interactive shells, file transfers, clipboard access, persistence management, and self-removal.
The malware overlaps with the KelpDAO incident report, which documented developer compromise preceding the $292 million bridge theft.
SentinelLabs’ related investigation also identified an Indian IT-services victim without cryptocurrency ties. Earlier Unit 42 research documented recruiter impersonation and malicious coding challenges targeting developers.
Organizations should restrict untrusted providers, verify checksums against trusted sources, inspect supplied lockfiles, and monitor unexpected provider-spawned processes.
SentinelLabs recommends scrutinizing unfamiliar registries and separating external interview assignments from corporate workstations, particularly where engineers hold cloud credentials or source-control access.
Indicators Of Compromise
| Indicator | File name | Description |
|---|---|---|
| 9d78ece09457907b730d139e4e0c64dd | terraform-provider-awsbeta_v1.0.0 | Trojanized Terraform provider |
| 73adaea97f003735335505858c1c6def | safari_updater | Bash script |
| 116f7189ed7b41f1b339a749d56e63be | HiraginoSans-Bold.woff | Encrypted Mach-O 64-bit x86_64 FLATROOF |
| be60c52ca8a01fef7dc15c2f0ebb77d8 | HiraginoSans-Regular.woff | Encrypted Mach-O 64-bit arm64 FLATROOF |
| 58fa0d651898446d5f5d2ed8a27a3330 | MalgunGothic-Bold.woff | Encrypted PE32+ FLATROOF |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

