SlowMist says North Korea-linked TraderTraitor used a malicious Terraform project in a fresh attack
SlowMist said on Sept. 22 that TraderTraitor, a threat group linked to North Korea and also tracked as UNC4899 and Jade Sleet, has launched another campaign. The group recently compromised an India-based IT services company that was not part of the crypto sector, showing that its targeting has widened beyond crypto-native firms. According to SlowMist, the attackers used fake job postings on GitHub and lured DevOps and crypto engineers with what appeared to be a technical interview assignment. After a victim downloaded the project, a malicious .terraform.lock.hcl file pointed to a Terraform Provider domain controlled by the attackers. Running terraform init then triggered the download and execution of a malicious Provider module. The attack ended with the deployment of the Rust/ARM64 backdoors FLATROOF and ROOFDECK on the victim’s macOS device. SlowMist said both malware families had also been used in the LayerZero attack. The tools can steal credentials and sensitive data, run shell commands, collect and exfiltrate files, and obtain access to cloud services and code repositories. SlowMist warned that the group may now be focusing more on developers’ cloud and API access, including AWS, GCP, OVH and OpenStack.








