Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties
DPRK TraderTraitor's FLATROOF and ROOFDECK macOS backdoors resurfaced on an Indian IT services victim, delivered via weaponized Terraform lock files in fake job interviews.
Following the April 2026 disclosure of the TraderTraitor attack on LayerZero that stole $292 million from KelpDAO via a fake crypto minting event and DDoS, SentinelOne identified a second victim: an India-based IT services provider with no cryptocurrency ties. FLATROOF (macOS.Gaslight) and ROOFDECK backdoors were found on a DevOps engineer's Apple Silicon MacBook, dormant from March 18 before beaconing on March 29. Campaigns use fake job interview lures with weaponized GitHub repositories whose .terraform.lock.hcl files pull malicious providers from typosquatted domains like registry.hashicorp-aws[.]com during terraform init. The backdoors collected API keys and escalated privileges into the victim's AWS and GCP environments.