Threat reportSupply ChainTL-2026-3071
Suspected TraderTraitor Group Uses Trojanized Terraform Provider to Deliver Cross-Platform FLATROOF and ROOFDECK Malware
Suspected TraderTraitor Group Uses Trojanized Terraform (TL-2026-3071), also tracked as FLATROOF, is a high-severity supply-chain compromise, first published 2026-10-09. It is attributed to TraderTraitor (North Korea) with low confidence, affects HashiCorp Terraform (provider plugin ecosystem; trojanized, maps to 25 MITRE ATT&CK techniques (T1008, T1027.009, T1027.013), and is covered by 9 detection rules and 55 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 25MITRE ATT&CK
- Actors
- 1TraderTraitor
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 55Indicators of compromise
Key facts for TL-2026-3071
- Threat ID
- TL-2026-3071
- Also known as
- FLATROOF, ROOFDECK, Trojanized Terraform Provider Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution
- TraderTraitor
- Attribution confidence
- LOW
- Nation-state nexus
- North Korea
- Motivation
- FINANCIAL
- Target sectors
- cryptocurrency, web3, technology, it-services, finance
- Target regions
- Global, india
- Detection rules
- 9
- Indicators of compromise
- 55
Malware and tooling in Suspected TraderTraitor Group Uses Trojanized Terraform
Malware and tooling: FLATROOF, ROOFDECK
How Suspected TraderTraitor Group Uses Trojanized Terraform works
Zscaler ThreatLabz reports a campaign in which a trojanized Terraform AWS provider (terraform-provider-awsbeta_v1.0.0) executes malicious code on load, fetches a Bash loader that retrieves encrypted payloads hidden inside decoy .woff font files, and installs the Rust-based FLATROOF backdoor/stealer and the ROOFDECK backdoor on Windows, macOS and Linux. Targets are cloud engineers and developers (notably crypto/Web3); attribution to North Korea-nexus TraderTraitor is suspected with limited confidence.
Zscaler ThreatLabz (Seongsu Park, published 2026-10-08) analyzed a campaign first uncovered in July 2026 that abuses the Terraform provider plugin model to compromise developer workstations and CI/CD systems. The trojanized Go binary terraform-provider-awsbeta_v1.0.0 masquerades as an AWS provider for HashiCorp Terraform. It adds a sibling package named awsbeta that is invoked directly from main(), so malicious code runs as soon as Terraform loads the provider. A session.lock run-once marker is written to the temp directory (TMPDIR, default /tmp). The provider downloads a Bash payload over HTTPS from a typosquatted HashiCorp-themed domain (diagnose.hashicorp-terraform.io), writes it to a file named safari_updater, marks it executable and launches it detached via sh -c.
The Bash loader selects an OS/architecture-specific payload by building a decoy font file name: font family encodes the OS (NotoSansCJK = Linux, HiraginoSans = macOS, MalgunGothic = Windows) and font style encodes the architecture (Bold = x86_64/amd64, Regular = aarch64/arm64, ExtraBold = ARMv7/ARMv6, Italic = 32-bit x86). Encrypted executables are appended to legitimate-looking .woff files after an @@ENDFONT@@ marker, then Base64-decoded and AES-256-CBC decrypted using Python, Node.js, Perl or OpenSSL, whichever is available. Files are fetched from three fallback sources in sequence: a dynamic-DNS host, a GitHub repository, and a Vercel-hosted site. On macOS the loader strips the com.apple.quarantine attribute with xattr and applies an ad hoc code signature before execution. Payloads are placed at $HOME/.config/git/update (Linux), $HOME/Library/com.apple.iTunesCloud/SystemUpdate (macOS) and $HOME/AppData/Local/Microsoft/Edge/service.exe (Windows).
FLATROOF is a Rust-based cross-platform backdoor and credential stealer. Its configuration is protected with PBKDF2-HMAC-SHA256 key derivation and AES-256-GCM and contains Telegram bot credentials, optional GitHub repo/token polling settings, a webhook C2 base/upload URL, platform-specific payload paths and persistence settings (Linux service named snap-imagent; macOS zlogout shell-logout persistence named imagent; Windows Run registry value powershell-config-service). C2 channels are the Telegram Bot API, GitHub API polling and an attacker-controlled HTTP webhook server. Commands cover system discovery, process and file management, command execution, payload download, data upload, persistence management, configuration changes and self-removal. FLATROOF also deploys embedded Python stealers that stage data in collected_data(.zip) and collect Chromium and Firefox profile data (history, cookies, logins, key4.db), shell history, installed applications, running processes and system information; macOS variants take Safari data and login.keychain-db, Linux variants the Chrome Safe Storage secret and keyring files, and Windows variants Chrome/Edge/Brave data, Credential Manager, PowerShell/CMD history and MetaMask, Phantom, Trust Wallet and Rabby extension data. The Windows stealer injects an XOR-encoded (0x37) 64-bit executable into a suspended Chromium process to recover app-bound encryption keys (written to [browser]_aes.txt) and drops cookie_copy_tool.exe as a fallback. FLATROOF checks for Cortex XDR/Traps paths and processes. ThreatLabz assesses the Python code as likely LLM-assisted (emoji-laden comments, repetitive exception handling, inconsistent naming).
ROOFDECK (Windows and macOS variants, near-identical) is a second-stage backdoor with a layered C2 discovery scheme: it reads a local configuration disguised as an application file, then pulls an encrypted server address from a Pastebin dead drop protected by an RSA signature (value and signature separated by ||) so third parties cannot redirect it, and falls back to Nostr profile metadata (attacker profile name 'tulip', 'website' field pointing to the current Pastebin URL) resolved through public relay lists. Capabilities include host/process/disk discovery, single-command and interactive reverse shell, file create/delete/move/compress/download/upload, clipboard read/write, background tasks, persistence install/remove/status, C2/polling reconfiguration, agent update and self-destruction.
Attribution: ThreatLabz links the activity to TraderTraitor (Jade Sleet, UNC4899, Pressure Chollima, Slow Pisces) based on targeting of cryptocurrency/Web3 developers via trojanized developer tooling, tactics consistent with prior TraderTraitor trojanized-app, Python-package and fake-job-offer operations, and overlap of FLATROOF/ROOFDECK with findings from the KelpDAO incident. ThreatLabz explicitly states it has not identified unique code similarities, shared infrastructure or cryptographic links sufficient to attribute with high confidence, so attribution is suspected only. SentinelLabs (report dated 2026-09-18) independently documented the same FLATROOF/ROOFDECK pair on an India-based IT services provider's macOS DevOps workstation, delivered via fake job-interview repositories containing weaponized .terraform.lock.hcl files pointing to attacker-controlled, HashiCorp-mimicking provider registries, broadening targeting beyond crypto entities. The Zscaler article does not state whether the trojanized provider was distributed through a public registry.
MITRE ATT&CK techniques used in TL-2026-3071
Command and Control
T1008 Fallback Channels; T1071.001 Web Protocols; T1102.001 Dead Drop Resolver; T1573.001 Symmetric Cryptography
Stealth
T1027.009 Embedded Payloads; T1027.013 Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1036.008 Masquerade File Type; T1055.012 Process Hollowing; T1070.004 File Deletion
Discovery
T1057 Process Discovery; T1082 System Information Discovery; T1217 Browser Information Discovery; T1518 Software Discovery
Execution
T1059.004 Unix Shell; T1059.006 Python
Initial Access
T1195.002 Compromise Software Supply Chain
Credential Access
T1539 Steal Web Session Cookie; T1552.003 Shell History; T1555.001 Keychain; T1555.004 Windows Credential Manager
Persistence
T1546.004 Unix Shell Configuration Modification
defense-impairment
T1553.001 Gatekeeper Bypass; T1553.002 Code Signing
Collection
Affected products and versions in Suspected TraderTraitor Group Uses Trojanized Terraform
- HashiCorp — Terraform (provider plugin ecosystem; trojanized terraform-provider-awsbeta_v1.0.0)
Vulnerable versions: terraform-provider-awsbeta_v1.0.0 (malicious provider, not an official HashiCorp release) - Multiple — Developer and CI/CD hosts running Windows, macOS and Linux (x86_64, arm64, ARM, x86)
Vulnerable versions: Any host executing the trojanized provider
Remediation for Suspected TraderTraitor Group Uses Trojanized Terraform
Immediate actions
- Hunt for terraform-provider-awsbeta, safari_updater, session.lock and the file hashes and network indicators listed in this record on developer workstations and CI/CD runners
- Block diagnose.hashicorp-terraform.io, supportaru.serveftp.com, arusupport-region1-webhook.online, delay.servehttp.com and stage-fashion365.vercel.app at DNS/proxy
- Rotate browser-stored credentials, session cookies, cloud keys and crypto wallet secrets on any host where the provider executed; isolate affected hosts
- Review .terraform.lock.hcl files and provider source addresses in repositories received from recruiters or third parties
Workarounds
- Run terraform init in disposable sandboxes for untrusted repositories
- Monitor Telegram Bot API, GitHub API, Pastebin and Nostr relay traffic from developer endpoints where not business-justified
Longer-term hardening
- Restrict Terraform provider sources to an allowlisted private registry or mirror and verify provider checksums/signatures against the official HashiCorp registry
- Deploy EDR on developer workstations and monitor process trees spawned by terraform provider plugins (sh -c, curl, python, openssl)
- Isolate development and CI/CD environments from production through network segmentation and short-lived credentials
- Enforce software supply chain verification and code signing policies for provider binaries; train engineers on fake job-interview coding test lures
Weaknesses (CWE) in Suspected TraderTraitor Group Uses Trojanized Terraform
Timeline of Suspected TraderTraitor Group Uses Trojanized Terraform
- Per SentinelLabs, FLATROOF and ROOFDECK were already present on the victim macOS disk; first observed implant execution followed on 2026-03-29 when the developer opened a DevOps-Automation workspace, with C2 connections within seconds
- Per SentinelLabs, a DevOps engineer at an India-based IT services provider cloned a fake-job-interview repository with a weaponized .terraform.lock.hcl, leading to FLATROOF/ROOFDECK on an Apple Silicon Mac (SentinelLabs-reported timeline; internally inconsistent in secondary coverage)
- Per SentinelLabs, FLATROOF re-armed ROOFDECK the day after the developer cloned the weaponized terraform-candidate-repo
- Per SentinelLabs, a stripped Stage 3 payload was downloaded and connected to C2, after which the original implants were deleted (anti-forensics)
- Per SentinelLabs, the final C2 beacon from the victim host was observed after sustained Stage 3 beaconing from early May
- Zscaler ThreatLabz uncovered the trojanized Terraform provider campaign (July 2026; day is approximate)
- SentinelLabs published 'Don't Call Us, We'll Call Your APIs' documenting FLATROOF and ROOFDECK on a second victim with no crypto ties
- eSecurity Planet reported North Korean actors hiding macOS backdoors in fake Terraform job tests
- Zscaler ThreatLabz published analysis attributing the activity, with low confidence, to TraderTraitor and released IOCs
Sources cited for Suspected TraderTraitor Group Uses Trojanized Terraform
- Suspected TraderTraitor Group Uses Trojanized Terraform Provider to Deliver Cross-Platform Malware (Zscaler ThreatLabz)
- Don't Call Us, We'll Call Your APIs: TraderTraitor Backdoors Resurface on Victim with No Crypto Ties (SentinelLabs)
- North Korean Hackers Hide Mac Backdoors in Fake Terraform Job Tests (eSecurity Planet)
- SentinelLabs Ties Second macOS Backdoor Attack to TraderTraitor (Technobezz)
- North Korean hackers linked to $290M heist from cryptocurrency platform (NK News)
- LayerZero says North Korea's Lazarus likely behind Kelp DAO exploit (The Block)
- The Good, the Bad and the Ugly in Cybersecurity - Week 39 (SentinelOne)
Detection coverage for TL-2026-3071
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3071 across Splunk SPL, Microsoft KQL and Sigma, covering 55 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.