{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/tradertraitor/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["TraderTraitor"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Terraform"],"_cs_severities":["high"],"_cs_tags":["macos","tradertraitor","supply-chain","social-engineering","cloud-security","devops"],"_cs_type":"threat","_cs_vendors":["HashiCorp"],"content_html":"\u003cp\u003eThe North Korean state-sponsored threat actor TraderTraitor (also known as UNC4899, PUKCHONG, and Jade Sleet) is actively conducting social engineering campaigns targeting DevOps and cryptocurrency engineers. The group creates fake job interview coding projects on GitHub, specifically using names like 'Northwind-IAC' and 'novacart-interview', to entice targets into downloading and running infrastructure-as-code projects.\u003c/p\u003e\n\u003cp\u003eThe malicious mechanism relies on weaponized '.terraform.lock.hcl' files. By configuring these files to point to attacker-controlled domains - such as registry.hashicorp-aws[.]com - the threat actor forces the execution of \u003ccode\u003eterraform init\u003c/code\u003e to download and run arbitrary malicious provider modules. Once the victim executes the code on their macOS workstation, the FLATROOF (macOS.Gaslight) and ROOFDECK backdoors are deployed. These backdoors enable the attackers to establish persistence, collect sensitive cloud API keys (AWS, GCP), and perform lateral movement. The campaign targets individuals in the IT services sector regardless of cryptocurrency ties, demonstrating a broad operational scope for gaining unauthorized access to production cloud environments.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker establishes contact with a target developer via social engineering through fake job interview lures on GitHub.\u003c/li\u003e\n\u003cli\u003eTarget downloads a weaponized coding project repository containing a modified '.terraform.lock.hcl' file.\u003c/li\u003e\n\u003cli\u003eVictim executes \u003ccode\u003eterraform init\u003c/code\u003e within the project directory on their macOS workstation.\u003c/li\u003e\n\u003cli\u003eTerraform client reaches out to an attacker-controlled registry domain (e.g., registry.hashicorp-terraform[.]io) to download the provider.\u003c/li\u003e\n\u003cli\u003eMalicious provider code is executed, deploying FLATROOF and ROOFDECK backdoors onto the local macOS system.\u003c/li\u003e\n\u003cli\u003eBackdoors perform a Gatekeeper bypass by executing \u003ccode\u003exattr -rd com.apple.quarantine\u003c/code\u003e and changing file permissions (\u003ccode\u003echmod +x\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eImplants establish persistent C2 communication via hardcoded IPs and transmit stolen cloud credentials to the threat actor.\u003c/li\u003e\n\u003cli\u003eAttacker uses stolen credentials to escalate privileges and access cloud infrastructure (AWS/GCP).\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful compromise results in full access to the victim's local developer workstation, theft of cloud environment credentials (AWS, GCP, OVH), and potential lateral movement into the organization's cloud production environments. This threat impacts DevOps teams and software engineers, potentially leading to widespread unauthorized access to private corporate infrastructure, data exfiltration, or further supply chain compromises.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAudit all \u003ccode\u003eterraform init\u003c/code\u003e activity and restrict egress traffic for developer workstations to verified Terraform registry domains (registry.terraform.io) only.\u003c/li\u003e\n\u003cli\u003eBlock the malicious provider registry domains listed in the IOC table at the DNS resolver level.\u003c/li\u003e\n\u003cli\u003eDeploy Sigma rules to detect unauthorized execution of \u003ccode\u003eterraform\u003c/code\u003e commands from non-standard directories or unusual network destinations.\u003c/li\u003e\n\u003cli\u003eMonitor macOS endpoints for suspicious process executions involving \u003ccode\u003ezsh\u003c/code\u003e spawning shell commands that include \u003ccode\u003exattr\u003c/code\u003e or \u003ccode\u003echmod +x\u003c/code\u003e on binaries located in application or temporary directories.\u003c/li\u003e\n\u003cli\u003eImplement security awareness training regarding the risks of running third-party infrastructure-as-code project repositories from untrusted sources.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T19:45:57Z","date_published":"2026-09-18T19:45:57Z","id":"https://feed.craftedsignal.io/briefs/2026-09-tradertraitor-macos-backdoors/","summary":"North Korean threat actor TraderTraitor is using fake job interview lures on GitHub containing weaponized Terraform lock files to deliver macOS backdoors to DevOps engineers, facilitating cloud credential theft.","title":"TraderTraitor Campaign Targeting DevOps Engineers via Weaponized Terraform Repositories","url":"https://feed.craftedsignal.io/briefs/2026-09-tradertraitor-macos-backdoors/"}],"language":"en","title":"CraftedSignal Threat Feed - Tradertraitor","version":"https://jsonfeed.org/version/1.1"}