North Korean TraderTraitor Hackers Use Fake Terraform Job Tests to Deploy macOS Backdoors
North Korean TraderTraitor used fake Terraform job tests to plant macOS backdoors and reach cloud accounts.
SentinelLABS reported that North Korean TraderTraitor operators, a Lazarus subgroup also known as UNC4899, PUKCHONG, and Jade Sleet, sent developers fake Terraform hiring tasks in GitHub repositories. Manipulated lock files caused terraform init to fetch malicious providers, which installed the FLATROOF and ROOFDECK macOS backdoors. The tools collected browser data, terminal history, and login keychains, persisted through a LaunchAgent, and supported theft of API keys used against AWS and Google Cloud. Observed victims included LayerZero and an Indian IT provider’s DevOps MacBook, with activity continuing into June.