Threat reportSupply ChainTL-2026-3071

Suspected TraderTraitor Group Uses Trojanized Terraform Provider to Deliver Cross-Platform FLATROOF and ROOFDECK Malware

highACTIVE

Suspected TraderTraitor Group Uses Trojanized Terraform (TL-2026-3071), also tracked as FLATROOF, is a high-severity supply-chain compromise, first published 2026-10-09. It is attributed to TraderTraitor (North Korea) with low confidence, affects HashiCorp Terraform (provider plugin ecosystem; trojanized, maps to 25 MITRE ATT&CK techniques (T1008, T1027.009, T1027.013), and is covered by 9 detection rules and 55 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
25MITRE ATT&CK
Actors
1TraderTraitor
Detection rules
9SPL · KQL · Sigma
IOCs
55Indicators of compromise

Key facts for TL-2026-3071

Threat ID
TL-2026-3071
Also known as
FLATROOF, ROOFDECK, Trojanized Terraform Provider Campaign
Severity
HIGH
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution
TraderTraitor
Attribution confidence
LOW
Nation-state nexus
North Korea
Motivation
FINANCIAL
Target sectors
cryptocurrency, web3, technology, it-services, finance
Target regions
Global, india
Detection rules
9
Indicators of compromise
55

Malware and tooling in Suspected TraderTraitor Group Uses Trojanized Terraform

Malware and tooling: FLATROOF, ROOFDECK

How Suspected TraderTraitor Group Uses Trojanized Terraform works

Zscaler ThreatLabz reports a campaign in which a trojanized Terraform AWS provider (terraform-provider-awsbeta_v1.0.0) executes malicious code on load, fetches a Bash loader that retrieves encrypted payloads hidden inside decoy .woff font files, and installs the Rust-based FLATROOF backdoor/stealer and the ROOFDECK backdoor on Windows, macOS and Linux. Targets are cloud engineers and developers (notably crypto/Web3); attribution to North Korea-nexus TraderTraitor is suspected with limited confidence.

Zscaler ThreatLabz (Seongsu Park, published 2026-10-08) analyzed a campaign first uncovered in July 2026 that abuses the Terraform provider plugin model to compromise developer workstations and CI/CD systems. The trojanized Go binary terraform-provider-awsbeta_v1.0.0 masquerades as an AWS provider for HashiCorp Terraform. It adds a sibling package named awsbeta that is invoked directly from main(), so malicious code runs as soon as Terraform loads the provider. A session.lock run-once marker is written to the temp directory (TMPDIR, default /tmp). The provider downloads a Bash payload over HTTPS from a typosquatted HashiCorp-themed domain (diagnose.hashicorp-terraform.io), writes it to a file named safari_updater, marks it executable and launches it detached via sh -c.

The Bash loader selects an OS/architecture-specific payload by building a decoy font file name: font family encodes the OS (NotoSansCJK = Linux, HiraginoSans = macOS, MalgunGothic = Windows) and font style encodes the architecture (Bold = x86_64/amd64, Regular = aarch64/arm64, ExtraBold = ARMv7/ARMv6, Italic = 32-bit x86). Encrypted executables are appended to legitimate-looking .woff files after an @@ENDFONT@@ marker, then Base64-decoded and AES-256-CBC decrypted using Python, Node.js, Perl or OpenSSL, whichever is available. Files are fetched from three fallback sources in sequence: a dynamic-DNS host, a GitHub repository, and a Vercel-hosted site. On macOS the loader strips the com.apple.quarantine attribute with xattr and applies an ad hoc code signature before execution. Payloads are placed at $HOME/.config/git/update (Linux), $HOME/Library/com.apple.iTunesCloud/SystemUpdate (macOS) and $HOME/AppData/Local/Microsoft/Edge/service.exe (Windows).

FLATROOF is a Rust-based cross-platform backdoor and credential stealer. Its configuration is protected with PBKDF2-HMAC-SHA256 key derivation and AES-256-GCM and contains Telegram bot credentials, optional GitHub repo/token polling settings, a webhook C2 base/upload URL, platform-specific payload paths and persistence settings (Linux service named snap-imagent; macOS zlogout shell-logout persistence named imagent; Windows Run registry value powershell-config-service). C2 channels are the Telegram Bot API, GitHub API polling and an attacker-controlled HTTP webhook server. Commands cover system discovery, process and file management, command execution, payload download, data upload, persistence management, configuration changes and self-removal. FLATROOF also deploys embedded Python stealers that stage data in collected_data(.zip) and collect Chromium and Firefox profile data (history, cookies, logins, key4.db), shell history, installed applications, running processes and system information; macOS variants take Safari data and login.keychain-db, Linux variants the Chrome Safe Storage secret and keyring files, and Windows variants Chrome/Edge/Brave data, Credential Manager, PowerShell/CMD history and MetaMask, Phantom, Trust Wallet and Rabby extension data. The Windows stealer injects an XOR-encoded (0x37) 64-bit executable into a suspended Chromium process to recover app-bound encryption keys (written to [browser]_aes.txt) and drops cookie_copy_tool.exe as a fallback. FLATROOF checks for Cortex XDR/Traps paths and processes. ThreatLabz assesses the Python code as likely LLM-assisted (emoji-laden comments, repetitive exception handling, inconsistent naming).

ROOFDECK (Windows and macOS variants, near-identical) is a second-stage backdoor with a layered C2 discovery scheme: it reads a local configuration disguised as an application file, then pulls an encrypted server address from a Pastebin dead drop protected by an RSA signature (value and signature separated by ||) so third parties cannot redirect it, and falls back to Nostr profile metadata (attacker profile name 'tulip', 'website' field pointing to the current Pastebin URL) resolved through public relay lists. Capabilities include host/process/disk discovery, single-command and interactive reverse shell, file create/delete/move/compress/download/upload, clipboard read/write, background tasks, persistence install/remove/status, C2/polling reconfiguration, agent update and self-destruction.

Attribution: ThreatLabz links the activity to TraderTraitor (Jade Sleet, UNC4899, Pressure Chollima, Slow Pisces) based on targeting of cryptocurrency/Web3 developers via trojanized developer tooling, tactics consistent with prior TraderTraitor trojanized-app, Python-package and fake-job-offer operations, and overlap of FLATROOF/ROOFDECK with findings from the KelpDAO incident. ThreatLabz explicitly states it has not identified unique code similarities, shared infrastructure or cryptographic links sufficient to attribute with high confidence, so attribution is suspected only. SentinelLabs (report dated 2026-09-18) independently documented the same FLATROOF/ROOFDECK pair on an India-based IT services provider's macOS DevOps workstation, delivered via fake job-interview repositories containing weaponized .terraform.lock.hcl files pointing to attacker-controlled, HashiCorp-mimicking provider registries, broadening targeting beyond crypto entities. The Zscaler article does not state whether the trojanized provider was distributed through a public registry.

MITRE ATT&CK techniques used in TL-2026-3071

Command and Control

T1008 Fallback Channels; T1071.001 Web Protocols; T1102.001 Dead Drop Resolver; T1573.001 Symmetric Cryptography

Stealth

T1027.009 Embedded Payloads; T1027.013 Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1036.008 Masquerade File Type; T1055.012 Process Hollowing; T1070.004 File Deletion

Discovery

T1057 Process Discovery; T1082 System Information Discovery; T1217 Browser Information Discovery; T1518 Software Discovery

Execution

T1059.004 Unix Shell; T1059.006 Python

Initial Access

T1195.002 Compromise Software Supply Chain

Credential Access

T1539 Steal Web Session Cookie; T1552.003 Shell History; T1555.001 Keychain; T1555.004 Windows Credential Manager

Persistence

T1546.004 Unix Shell Configuration Modification

defense-impairment

T1553.001 Gatekeeper Bypass; T1553.002 Code Signing

Collection

T1560.001 Archive via Utility

Affected products and versions in Suspected TraderTraitor Group Uses Trojanized Terraform

  • HashiCorp — Terraform (provider plugin ecosystem; trojanized terraform-provider-awsbeta_v1.0.0)
    Vulnerable versions: terraform-provider-awsbeta_v1.0.0 (malicious provider, not an official HashiCorp release)
  • Multiple — Developer and CI/CD hosts running Windows, macOS and Linux (x86_64, arm64, ARM, x86)
    Vulnerable versions: Any host executing the trojanized provider

Remediation for Suspected TraderTraitor Group Uses Trojanized Terraform

Immediate actions

  • Hunt for terraform-provider-awsbeta, safari_updater, session.lock and the file hashes and network indicators listed in this record on developer workstations and CI/CD runners
  • Block diagnose.hashicorp-terraform.io, supportaru.serveftp.com, arusupport-region1-webhook.online, delay.servehttp.com and stage-fashion365.vercel.app at DNS/proxy
  • Rotate browser-stored credentials, session cookies, cloud keys and crypto wallet secrets on any host where the provider executed; isolate affected hosts
  • Review .terraform.lock.hcl files and provider source addresses in repositories received from recruiters or third parties

Workarounds

  • Run terraform init in disposable sandboxes for untrusted repositories
  • Monitor Telegram Bot API, GitHub API, Pastebin and Nostr relay traffic from developer endpoints where not business-justified

Longer-term hardening

  • Restrict Terraform provider sources to an allowlisted private registry or mirror and verify provider checksums/signatures against the official HashiCorp registry
  • Deploy EDR on developer workstations and monitor process trees spawned by terraform provider plugins (sh -c, curl, python, openssl)
  • Isolate development and CI/CD environments from production through network segmentation and short-lived credentials
  • Enforce software supply chain verification and code signing policies for provider binaries; train engineers on fake job-interview coding test lures

Weaknesses (CWE) in Suspected TraderTraitor Group Uses Trojanized Terraform

CWE-506, CWE-494

Timeline of Suspected TraderTraitor Group Uses Trojanized Terraform

  • Per SentinelLabs, FLATROOF and ROOFDECK were already present on the victim macOS disk; first observed implant execution followed on 2026-03-29 when the developer opened a DevOps-Automation workspace, with C2 connections within seconds
  • Per SentinelLabs, a DevOps engineer at an India-based IT services provider cloned a fake-job-interview repository with a weaponized .terraform.lock.hcl, leading to FLATROOF/ROOFDECK on an Apple Silicon Mac (SentinelLabs-reported timeline; internally inconsistent in secondary coverage)
  • Per SentinelLabs, FLATROOF re-armed ROOFDECK the day after the developer cloned the weaponized terraform-candidate-repo
  • Per SentinelLabs, a stripped Stage 3 payload was downloaded and connected to C2, after which the original implants were deleted (anti-forensics)
  • Per SentinelLabs, the final C2 beacon from the victim host was observed after sustained Stage 3 beaconing from early May
  • Zscaler ThreatLabz uncovered the trojanized Terraform provider campaign (July 2026; day is approximate)
  • SentinelLabs published 'Don't Call Us, We'll Call Your APIs' documenting FLATROOF and ROOFDECK on a second victim with no crypto ties
  • eSecurity Planet reported North Korean actors hiding macOS backdoors in fake Terraform job tests
  • Zscaler ThreatLabz published analysis attributing the activity, with low confidence, to TraderTraitor and released IOCs

Sources cited for Suspected TraderTraitor Group Uses Trojanized Terraform

Detection coverage for TL-2026-3071

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3071 across Splunk SPL, Microsoft KQL and Sigma, covering 55 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
55 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats