North Korean TraderTraitor Hackers Use Fake Terraform Job Tests to Deploy macOS Backdoors
North Korean TraderTraitor used fake Terraform job tests to plant macOS backdoors and reach cloud accounts.
SentinelLABS reported that North Korean TraderTraitor operators, a Lazarus subgroup also known as UNC4899, PUKCHONG, and Jade Sleet, sent developers fake Terraform hiring tasks in GitHub repositories. Manipulated lock files caused terraform init to fetch malicious providers, which installed the FLATROOF and ROOFDECK macOS backdoors. The tools collected browser data, terminal history, and login keychains, persisted through a LaunchAgent, and supported theft of API keys used against AWS and Google Cloud. Observed victims included LayerZero and an Indian IT provider’s DevOps MacBook, with activity continuing into June.
- TraderTraitor is a Lazarus subgroup also tracked as UNC4899, PUKCHONG, and Jade Sleet.
- Fake GitHub Terraform assignments pointed lock files at attacker-controlled providers.
- FLATROOF and ROOFDECK stole macOS data and supported access to AWS and GCP.
- Victims included LayerZero and an Indian IT provider’s DevOps MacBook.
- ROOFDECK used a LaunchAgent and resolved servers through the Nostr network.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | anesthesiaschool.com | .]com Domain associated with the ub certificate user Domain anesthesiaschool[.]com Domain associated with the ub certificate user Domain app |
| domain | cprapid.com | ndpoint, with host resolved at runtime Domain 185-66-91-112.cprapid[.]com Domain associated with the ub certificate user Domain 213 |
| domain | freehealth.lat | m Domain associated with the ub certificate user Domain www.freehealth[.]lat Domain associated with the ub certificate user Domain www |
| domain | galaxy-royal.online | .]com Domain associated with the ub certificate user Domain galaxy-royal[.]online Domain associated with the ub certificate user Domain gam |
| domain | github.com | er domain used in weaponized repositories GitHub repository github[.]com/exubient0/terraform-candidate-repo Repository containing |
| domain | grenight.com | .hubpage[.]cloud ROOFDECK command-and-control server Domain grenight[.]com ROOFDECK command-and-control server IP address 176.97.114 |
Full article1,222 words · extracted from cybersecuritynews.com · click to collapse
North Korean threat actors are using fake Terraform job tests to compromise macOS developers and reach cloud systems. The campaign shows how a routine coding assignment can become an entry point for data theft, remote control, and deeper network intrusion.
The activity is tied to TraderTraitor, a financially motivated Lazarus subgroup also tracked as UNC4899, PUKCHONG, and Jade Sleet.
It follows a major incident involving LayerZero, and investigators found an unrelated Indian IT services provider affected by the backdoors.
SentinelLABS said in a report shared with Cyber Security News (CSN) that the attackers expanded their focus beyond crypto firms.
The finding shows North Korean operators pursue developers, cloud administrators, and people who hold valuable technical access.
The risk is not limited to one employer or one industry. A developer laptop can hold cloud credentials, source-code access, deployment permissions, and application programming interface keys, making it a high-value bridge into corporate infrastructure.
Similar recruiter-led traps have appeared in recent Lazarus interview campaigns, where trust in a supposed hiring process becomes the initial weakness.
North Korean TraderTraitor Hackers Use Fake Terraform Job Tests
TraderTraitor approached job seekers with infrastructure-focused interview assignments hosted in GitHub repositories. The targets’ public profiles commonly showed DevOps, cryptocurrency, or financial-technology experience, allowing the operators to tailor projects that looked relevant to their professional skills.
Researchers identified repositories using names such as Northwind-IAC, novacart-interview, and terraform-candidate-repo.
Each lure contained a manipulated .terraform.lock.hcl file that directed Terraform toward an attacker-controlled provider registry instead of a legitimate source. Running terraform init then downloaded and executed malicious provider modules.
.webp)
The tactic is particularly effective because lock files appear to be ordinary project metadata. One candidate noticed a suspicious lookalike provider and removed it, suggesting that careful review can stop an infection before code runs.
That concern echoes malicious Terraform registry attacks, which demonstrated the danger of compromised infrastructure packages. The operators used this access to install FLATROOF and ROOFDECK backdoors on macOS.
In the earlier LayerZero intrusion, the tools helped collect API keys and supported privilege escalation into Amazon Web Services and Google Cloud Platform environments. The campaign therefore targets both the endpoint and the cloud access connected to it.
macOS Implants Expand Control
At the Indian IT services victim, the attackers compromised an Apple Silicon MacBook used by a DevOps engineer. The machine routinely managed AWS, OVH, and OpenStack resources, holding cloud credentials and source-control access. Telemetry showed both implants on disk by March 18, before activity began on March 29.
FLATROOF was disguised as SystemUpdate and was designed for initial collection and follow-on delivery. It can run shell commands, upload files through Telegram, gather browser data and terminal histories, list installed applications, record running processes, profile the system, and copy the login keychain.
Its behavior aligns with the Rust macOS backdoor investigation, which documented its data-stealing capability. ROOFDECK, masquerading as iSync, offered broader control.
.webp)
It can search for valuable files, execute commands, create encrypted archives, transfer data, read the clipboard, and establish persistence through a LaunchAgent. It also resolves command servers through the decentralized Nostr network, making its communications more flexible for operators.
The attackers later deployed a stripped ROOFDECK variant called loginwindow, removed the earlier implants, and continued beaconing through June 1.
This shift suggests that the group can refresh its tooling during an intrusion and reduce evidence left on the victim device. It also reflects the persistence seen when North Korean Git hooks spread malware, another developer-focused campaign.
Organizations should treat staff with cloud and source-control privileges as a sensitive monitoring group. Security teams should investigate unsigned programs launched from home directories, unusual child processes from development tools, unexpected encrypted outbound traffic, and unsolicited interview repositories.
Developers should avoid opening external assessments on corporate workstations and verify every provider in a Terraform lock file before running it.
Provider names that do not use the known registry.terraform.io namespace merit immediate scrutiny, while even packages from official registries should be traced to their source code and trusted publisher.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-1 | 02df07a173ab03b82a4fb6a08973fff8b1467f28 | FLATROOF, masquerading as SystemUpdate |
| SHA-1 | c491d477dbe0ae04e9aed9dbe237144c03f73ec4 | ROOFDECK, masquerading as iSync |
| SHA-1 | 5728b11d30586bbfc1d8bd12df1c722a06e767a2 | Stripped ROOFDECK, masquerading as loginwindow |
| Domain | technicais.sytes[.]net | FLATROOF command-and-control server |
| Domain | storage.hubpage[.]cloud | ROOFDECK command-and-control server |
| Domain | grenight[.]com | ROOFDECK command-and-control server |
| IP address | 176.97.114[.]232 | FLATROOF C2 associated with technicais.sytes[.]net |
| IP address | 45.11.59[.]140 | ROOFDECK C2 associated with storage.hubpage[.]cloud |
| IP address | 85.137.56[.]245 | ROOFDECK C2 associated with grenight[.]com |
| IP address | 85.137.56[.]10 | ROOFDECK staging server |
| File path | ~/Library/com.apple.iTunesCloud/SystemUpdate | FLATROOF binary path |
| File path | ~/Library/com.apple.internal.ck/iSync | ROOFDECK binary path |
| File path | ~/Library/com.apple.appleaccountd/loginwindow | Stripped ROOFDECK binary path |
| File | /private/tmp/.pipe-airway | ROOFDECK inter-process communication pipe |
| File | $TMPDIR/tmp*.lock | FLATROOF lock file |
| Workspace | ~/DevOps-Automation/cloudshield | Malicious workspace path |
| TLS certificate SHA-256 | 4b2d3e8ccce8920a6d01e7d02b84236545a20e5f754b3eec253f8b416b731daa | Custom certificate used for TLS communication |
| TLS certificate SHA-1 | 4ad92bf92ee614b05c340ce17bef7b6ef5a25e82 | Custom certificate used for TLS communication |
| TLS certificate serial | 1cd6d13ff15adbf7a42025d10ec99b4a | Custom certificate serial number |
| TLS certificate subject/issuer | O=mkcert development CA, OU=ub@ub-Standard-PC-Q35-ICH9-2009, CN=mkcert ub@ub-Standard-PC-Q35-ICH9-2009 | Self-signed ROOFDECK TLS certificate metadata |
| Persistence | ~/Library/LaunchAgents/*.plist | Label starts with com., ProgramArguments includes --type=renderer, and RunAtLoad=true |
| Configuration file | $HOME/.config/.repl_history | ROOFDECK configuration file |
| HTTPS endpoint | /app_version | ROOFDECK tasking endpoint, with host resolved at runtime |
| Domain | 185-66-91-112.cprapid[.]com | Domain associated with the ub certificate user |
| Domain | 213-111-146-132.cprapid[.]com | Domain associated with the ub certificate user |
| Domain | anesthesiaschool[.]com | Domain associated with the ub certificate user |
| Domain | app.heyhay[.]online | Domain associated with the ub certificate user |
| Domain | dela.servehttp[.]com | Domain associated with the ub certificate user |
| Domain | galaxy-royal[.]online | Domain associated with the ub certificate user |
| Domain | game.galaxy-royal[.]online | Domain associated with the ub certificate user |
| Domain | heyhay[.]online | Domain associated with the ub certificate user |
| Domain | mactroubleshoots[.]pro | Domain associated with the ub certificate user |
| Domain | mx01.galaxy-royal[.]online | Domain associated with the ub certificate user |
| Domain | ns4.galaxy-royal[.]online | Domain associated with the ub certificate user |
| Domain | tinklify[.]com | Domain associated with the ub certificate user |
| Domain | update.heyhay[.]online | Domain associated with the ub certificate user |
| Domain | vaimage[.]com | Domain associated with the ub certificate user |
| Domain | wss.sytes[.]net | Domain associated with the ub certificate user |
| Domain | www.anesthesiaschool[.]com | Domain associated with the ub certificate user |
| Domain | www.freehealth[.]lat | Domain associated with the ub certificate user |
| Domain | www.heyhay[.]online | Domain associated with the ub certificate user |
| Domain | www.mactroubleshoots[.]pro | Domain associated with the ub certificate user |
| Domain | www.tinklify[.]com | Domain associated with the ub certificate user |
| Malicious provider domain | registry.hashicorp-aws[.]com | Typosquatted Terraform provider domain used in weaponized repositories |
| Malicious provider domain | registry.hashicorp-aws[.]io | Typosquatted Terraform provider domain used in weaponized repositories |
| Malicious provider domain | registry.hashicorp-terraform[.]io | Typosquatted Terraform provider domain used in weaponized repositories |
| GitHub repository | github[.]com/exubient0/terraform-candidate-repo | Repository containing a weaponized Terraform lock file |
| GitHub repository | github[.]com/radupopa369/gtn-candidate-repo | Repository containing a weaponized Terraform lock file |
| GitHub repository | github[.]com/chainstacker/Northwind-IAC | Repository associated with the hashicorp-aws[.]io provider lure |
| GitHub repository | github[.]com/RyanLRay/Technical-Assessments | Repository README referencing the weaponized provider domain |
| GitHub repository | github[.]com/Steed-LHV/assessment | Repository README referencing the hashicorp-terraform[.]io provider domain |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.