# Suspected TraderTraitor Group Uses Trojanized Terraform Provider to Deliver Cross-Platform FLATROOF and ROOFDECK Malware

> Zscaler ThreatLabz reports a campaign in which a trojanized Terraform AWS provider (terraform-provider-awsbeta_v1.0.0) executes malicious code on load, fetches a Bash loader that retrieves encrypted payloads hidden inside decoy .woff font files, and installs the Rust-based FLATROOF backdoor/stealer and the ROOFDECK backdoor on Windows, macOS and Linux. Targets are cloud engineers and developers (notably crypto/Web3); attribution to North Korea-nexus TraderTraitor is suspected with limited confidence.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3071
- **ID:** TL-2026-3071
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Actor:** TraderTraitor (North Korea)
- **Detections:** 9 · **IOCs:** 55 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Zscaler ThreatLabz (Seongsu Park, published 2026-10-08) analyzed a campaign first uncovered in July 2026 that abuses the Terraform provider plugin model to compromise developer workstations and CI/CD systems. The trojanized Go binary terraform-provider-awsbeta_v1.0.0 masquerades as an AWS provider for HashiCorp Terraform. It adds a sibling package named awsbeta that is invoked directly from main(), so malicious code runs as soon as Terraform loads the provider. A session.lock run-once marker is written to the temp directory (TMPDIR, default /tmp). The provider downloads a Bash payload over HTTPS from a typosquatted HashiCorp-themed domain (diagnose.hashicorp-terraform.io), writes it to a file named safari_updater, marks it executable and launches it detached via sh -c.

The Bash loader selects an OS/architecture-specific payload by building a decoy font file name: font family encodes the OS (NotoSansCJK = Linux, HiraginoSans = macOS, MalgunGothic = Windows) and font style encodes the architecture (Bold = x86_64/amd64, Regular = aarch64/arm64, ExtraBold = ARMv7/ARMv6, Italic = 32-bit x86). Encrypted executables are appended to legitimate-looking .woff files after an @@ENDFONT@@ marker, then Base64-decoded and AES-256-CBC decrypted using Python, Node.js, Perl or OpenSSL, whichever is available. Files are fetched from three fallback sources in sequence: a dynamic-DNS host, a GitHub repository, and a Vercel-hosted site. On macOS the loader strips the com.apple.quarantine attribute with xattr and applies an ad hoc code signature before execution. Payloads are placed at $HOME/.config/git/update (Linux), $HOME/Library/com.apple.iTunesCloud/SystemUpdate (macOS) and $HOME/AppData/Local/Microsoft/Edge/service.exe (Windows).

FLATROOF is a Rust-based cross-platform backdoor and credential stealer. Its configuration is protected with PBKDF2-HMAC-SHA256 key derivation and AES-256-GCM and contains Telegram bot credentials, optional GitHub repo/token polling settings, a webhook C2 base/upload URL, platform-specific payload paths and persistence settings (Linux service named snap-imagent; macOS zlogout shell-logout persistence named imagent; Windows Run registry value powershell-config-service). C2 channels are the Telegram Bot API, GitHub API polling and an attacker-controlled HTTP webhook server. Commands cover system discovery, process and file management, command execution, payload download, data upload, persistence management, configuration changes and self-removal. FLATROOF also deploys embedded Python stealers that stage data in collected_data(.zip) and collect Chromium and Firefox profile data (history, cookies, logins, key4.db), shell history, installed applications, running processes and system information; macOS variants take Safari data and login.keychain-db, Linux variants the Chrome Safe Storage secret and keyring files, and Windows variants Chrome/Edge/Brave data, Credential Manager, PowerShell/CMD history and MetaMask, Phantom, Trust Wallet and Rabby extension data. The Windows stealer injects an XOR-encoded (0x37) 64-bit executable into a suspended Chromium process to recover app-bound encryption keys (written to [browser]_aes.txt) and drops cookie_copy_tool.exe as a fallback. FLATROOF checks for Cortex XDR/Traps paths and processes. ThreatLabz assesses the Python code as likely LLM-assisted (emoji-laden comments, repetitive exception handling, inconsistent naming).

ROOFDECK (Windows and macOS variants, near-identical) is a second-stage backdoor with a layered C2 discovery scheme: it reads a local configuration disguised as an application file, then pulls an encrypted server address from a Pastebin dead drop protected by an RSA signature (value and signature separated by ||) so third parties cannot redirect it, and falls back to Nostr profile metadata (attacker profile name 'tulip', 'website' field pointing to the current Pastebin URL) resolved through public relay lists. Capabilities include host/process/disk discovery, single-command and interactive reverse shell, file create/delete/move/compress/download/upload, clipboard read/write, background tasks, persistence install/remove/status, C2/polling reconfiguration, agent update and self-destruction.

Attribution: ThreatLabz links the activity to TraderTraitor (Jade Sleet, UNC4899, Pressure Chollima, Slow Pisces) based on targeting of cryptocurrency/Web3 developers via trojanized developer tooling, tactics consistent with prior TraderTraitor trojanized-app, Python-package and fake-job-offer operations, and overlap of FLATROOF/ROOFDECK with findings from the KelpDAO incident. ThreatLabz explicitly states it has not identified unique code similarities, shared infrastructure or cryptographic links sufficient to attribute with high confidence, so attribution is suspected only. SentinelLabs (report dated 2026-09-18) independently documented the same FLATROOF/ROOFDECK pair on an India-based IT services provider's macOS DevOps workstation, delivered via fake job-interview repositories containing weaponized .terraform.lock.hcl files pointing to attacker-controlled, HashiCorp-mimicking provider registries, broadening targeting beyond crypto entities. The Zscaler article does not state whether the trojanized provider was distributed through a public registry.

## MITRE ATT&CK

- T1195.002 Compromise Software Supply Chain
- T1059.004 Unix Shell
- T1059.006 Python
- T1546.004 Unix Shell Configuration Modification
- T1036.005 Match Legitimate Resource Name or Location
- T1036.008 Masquerade File Type
- T1027.009 Embedded Payloads
- T1027.013 Encrypted/Encoded File
- T1553.001 Gatekeeper Bypass
- T1055.012 Process Hollowing
- T1555.001 Keychain
- T1555.004 Windows Credential Manager
- T1552.003 Shell History
- T1539 Steal Web Session Cookie
- T1082 System Information Discovery
- T1217 Browser Information Discovery
- T1560.001 Archive via Utility
- T1071.001 Web Protocols
- T1102.001 Dead Drop Resolver
- T1008 Fallback Channels
- T1573.001 Symmetric Cryptography
- T1553.002 Code Signing
- T1070.004 File Deletion
- T1057 Process Discovery
- T1518 Software Discovery

## Sources

- [Suspected TraderTraitor Group Uses Trojanized Terraform Provider to Deliver Cross-Platform Malware (Zscaler ThreatLabz)](https://www.zscaler.com/blogs/security-research/suspected-tradertraitor-group-uses-trojanized-terraform-provider-deliver)
- [Don't Call Us, We'll Call Your APIs: TraderTraitor Backdoors Resurface on Victim with No Crypto Ties (SentinelLabs)](https://www.sentinelone.com/labs/dont-call-us-well-call-your-apis-tradertraitor-backdoors-resurface-on-victim-with-no-crypto-ties/)
- [North Korean Hackers Hide Mac Backdoors in Fake Terraform Job Tests (eSecurity Planet)](https://www.esecurityplanet.com/threats/news-north-korean-terraform-malware/)
- [SentinelLabs Ties Second macOS Backdoor Attack to TraderTraitor (Technobezz)](https://www.technobezz.com/news/sentinelabs-second-macos-backdoor-traderattraitor)
- [North Korean hackers linked to $290M heist from cryptocurrency platform (NK News)](https://nknews.org/pro/north-korean-hackers-linked-to-290m-heist-from-cryptocurrency-platform/)
- [LayerZero says North Korea's Lazarus likely behind Kelp DAO exploit (The Block)](https://theblock.co/post/398028/layerzero-kelp-dao-lazarus)
- [The Good, the Bad and the Ugly in Cybersecurity - Week 39 (SentinelOne)](https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-39-8/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3071
