SlowMist said on Sept. 22 that TraderTraitor, a threat group linked to North Korea and also tracked as UNC4899 and Jade Sleet, has launched another campaign. The group recently compromised an India-based IT services company that was not part of the crypto sector, showing that its targeting has widened beyond crypto-native firms.
According to SlowMist, the attackers used fake job postings on GitHub and lured DevOps and crypto engineers with what appeared to be a technical interview assignment. After a victim downloaded the project, a malicious .terraform.lock.hcl file pointed to a Terraform Provider domain controlled by the attackers. Running terraform init then triggered the download and execution of a malicious Provider module.
The attack ended with the deployment of the Rust/ARM64 backdoors FLATROOF and ROOFDECK on the victim’s macOS device. SlowMist said both malware families had also been used in the LayerZero attack. The tools can steal credentials and sensitive data, run shell commands, collect and exfiltrate files, and obtain access to cloud services and code repositories. SlowMist warned that the group may now be focusing more on developers’ cloud and API access, including AWS, GCP, OVH and OpenStack.
BlockBeats reported on Sept. 22 that, according to SlowMist, the North Korea-linked threat group TraderTraitor, also known as UNC4899 and Jade Sleet, has launched another attack and recently compromised an IT services company in India that was unrelated to the crypto industry.
Fake GitHub recruiting posts used as the lure
SlowMist said the attackers posted fake job listings on GitHub and used a so-called technical interview assignment to phish DevOps engineers and crypto engineers. After a target downloaded the project, a malicious .terraform.lock.hcl file pointed to a Terraform Provider domain controlled by the attackers.
Once the victim ran terraform init, the process triggered the download and execution of a malicious Provider module.
FLATROOF and ROOFDECK deployed on macOS
The attack ultimately deployed the Rust/ARM64 backdoors FLATROOF and ROOFDECK on the victim’s macOS device. SlowMist said both malware families had previously been used in the LayerZero attack.
According to the disclosure, the malware can:
- steal credentials and sensitive data;
- execute shell commands;
- collect and exfiltrate files;
- obtain access to cloud services and code repositories.
Targeting now extends beyond crypto
SlowMist warned that TraderTraitor’s targets in this campaign were no longer limited to the crypto sector. The attackers may be paying closer attention to developers’ cloud and API access, including AWS, GCP, OVH and OpenStack.
SlowMist advised companies to treat unfamiliar Terraform Providers and code repositories supplied by recruiters with caution, and to avoid running unverified interview projects on personal or corporate development devices.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.