Suspected TraderTraitor Hackers Trojanize Terraform Provider to Deploy Cross-Platform Malware
Suspected North Korean hackers trojanized a Terraform provider to install FLATROOF and ROOFDECK on developer machines.
Zscaler ThreatLabz analyzed a July 2026 campaign that used a trojanized Terraform provider, terraform-provider-awsbeta_v1.0.0, to deploy cross-platform malware on developer systems. A Bash loader fetches encrypted payloads disguised as font files, installing the Rust backdoor FLATROOF for credential and wallet theft and ROOFDECK for remote control across Linux, macOS, and Windows. Researchers noted tactical overlap with North Korea-linked TraderTraitor, also tracked as Jade Sleet, UNC4899, Pressure Chollima, and Slow Pisces, but said they lack high-confidence attribution. How the provider was first distributed remains unresolved; related reporting has connected similar developer targeting to the KelpDAO bridge theft and an Indian IT-services compromise.
- Trojanized terraform-provider-awsbeta_v1.0.0 runs malicious code when Terraform starts the plugin.
- FLATROOF steals browser, keychain, and cryptocurrency-wallet data on Linux, macOS, and Windows.
- ROOFDECK supports shells, file transfer, clipboard access, and remote command-and-control.
- Zscaler sees TraderTraitor overlap but says attribution is not high confidence.
- The provider's initial delivery path remains unknown.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | hashicorp-terraform.io | e temporary directory before downloading a Bash loader from hashicorp-terraform[.]io . It saves the script as safari_updater , grants executio |
| md5 | 116f7189ed7b41f1b339a749d56e63be | 73adaea97f003735335505858c1c6def safari_updater Bash script 116f7189ed7b41f1b339a749d56e63be HiraginoSans-Bold.woff Encrypted Mach-O 64-bit x86_64 FLATR |
| md5 | 58fa0d651898446d5f5d2ed8a27a3330 | inoSans-Regular.woff Encrypted Mach-O 64-bit arm64 FLATROOF 58fa0d651898446d5f5d2ed8a27a3330 MalgunGothic-Bold.woff Encrypted PE32+ FLATROOF Note: IP ad |
| md5 | 73adaea97f003735335505858c1c6def | aform-provider-awsbeta_v1.0.0 Trojanized Terraform provider 73adaea97f003735335505858c1c6def safari_updater Bash script 116f7189ed7b41f1b339a749d56e63be |
| md5 | 9d78ece09457907b730d139e4e0c64dd | s. Indicators Of Compromise Indicator File name Description 9d78ece09457907b730d139e4e0c64dd terraform-provider-awsbeta_v1.0.0 Trojanized Terraform prov |
| md5 | be60c52ca8a01fef7dc15c2f0ebb77d8 |
Full article712 words · extracted from gbhackers.com · click to collapse
A campaign in July 2026 using a trojanized Terraform provider to deploy cross-platform malware against developer environments.
The operation delivers FLATROOF for credential theft and initial access, followed by ROOFDECK for broader remote control.
Attribution remains provisional. ThreatLabz found similarities in targeting, tooling, and tactics but lacked unique code matches, shared infrastructure, or cryptographic evidence sufficient for independent, high-confidence attribution.
The initial delivery mechanism for the analyzed provider also remains unresolved.
The Go binary, terraform-provider-awsbeta_v1.0.0, impersonates an AWS Terraform provider while retaining a functional provider scaffold.
Attackers inserted a malicious awsbeta package and invoked it directly from main, triggering execution when Terraform starts the plugin.
The implant checks for session.lock in the temporary directory before downloading a Bash loader from hashicorp-terraform[.]io.
It saves the script as safari_updater, grants execution permissions, launches a detached process, and creates the marker to suppress repeat execution. Normal provider behavior continues, reducing visible disruption.
The loader identifies the operating system and processor architecture, then selects an encrypted payload disguised as a .woff font.

Zscaler ThreatLabz said in a report shared with GBhackers, significant overlap with TraderTraitor, a North Korean state-backed actor tracked as Jade Sleet, UNC4899, Pressure Chollima, and Slow Pisces.
Terraform Supply Chain
Linux, macOS, and Windows use NotoSansCJK, HiraginoSans, and MalgunGothic filenames respectively; Windows execution requires a compatible Unix-like shell environment.
The first is a 64-bit Windows executable that is decoded using the XOR key 0x37 and injected into a suspended Chromium process to recover master encryption keys.
Downloads fall back across dynamic DNS infrastructure, GitHub, and Vercel. Each file combines decoy font content with an @@ENDFONT@@ marker and encrypted executable.

The loader extracts the appended content, Base64-decodes it, and applies AES-256-CBC decryption through available Python, Node.js, Perl, or OpenSSL tooling.
On macOS, it removes the quarantine attribute and applies an ad hoc signature before execution.
The Rust-based FLATROOF backdoor decrypts its configuration using PBKDF2-HMAC-SHA256 and AES-256-GCM.
Its code supports Telegram, GitHub API polling, and attacker-controlled HTTP webhooks, although individual samples do not necessarily configure every channel.
Persistence varies by platform: Linux services, macOS shell logout mechanisms, and Windows registry Run values.
Embedded Python collectors harvest browser databases, cookies, saved credential artifacts, terminal histories, application inventories, and host information.
Platform-specific collection includes Linux keyrings, macOS login.keychain-db, and Windows Credential Manager entries. Windows scripts additionally target MetaMask, Phantom, Trust Wallet, and Rabby extension data.
An embedded native component executes inside a suspended Chromium process to recover browser encryption keys.

ROOFDECK resolves its command-and-control address through local configuration, a signed and encrypted Pastebin dead drop, or Nostr profile metadata.
RSA signature verification prevents unauthorized replacement of the accepted server address. Nostr’s profile website field can redirect the implant to the current Pastebin location.
Once connected over HTTP or WebSocket endpoints, ROOFDECK supports reconnaissance, interactive shells, file transfers, clipboard access, persistence management, and self-removal.
The malware overlaps with the KelpDAO incident report, which documented developer compromise preceding the $292 million bridge theft.
SentinelLabs’ related investigation also identified an Indian IT-services victim without cryptocurrency ties. Earlier Unit 42 research documented recruiter impersonation and malicious coding challenges targeting developers.
Organizations should restrict untrusted providers, verify checksums against trusted sources, inspect supplied lockfiles, and monitor unexpected provider-spawned processes.
SentinelLabs recommends scrutinizing unfamiliar registries and separating external interview assignments from corporate workstations, particularly where engineers hold cloud credentials or source-control access.
Indicators Of Compromise
| Indicator | File name | Description |
|---|---|---|
| 9d78ece09457907b730d139e4e0c64dd | terraform-provider-awsbeta_v1.0.0 | Trojanized Terraform provider |
| 73adaea97f003735335505858c1c6def | safari_updater | Bash script |
| 116f7189ed7b41f1b339a749d56e63be | HiraginoSans-Bold.woff | Encrypted Mach-O 64-bit x86_64 FLATROOF |
| be60c52ca8a01fef7dc15c2f0ebb77d8 | HiraginoSans-Regular.woff | Encrypted Mach-O 64-bit arm64 FLATROOF |
| 58fa0d651898446d5f5d2ed8a27a3330 | MalgunGothic-Bold.woff | Encrypted PE32+ FLATROOF |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.