Hackers Weaponize Terraform Lock Files to Infect DevOps Engineers With macOS Backdoors
North Korea-linked TraderTraitor uses weaponized Terraform lock files in fake job-interview GitHub repos to deploy FLATROOF and ROOFDECK macOS backdoors on DevOps engineers.
SentinelOne reports that TraderTraitor (UNC4899, Jade Sleet, PUKCHONG), a DPRK-aligned Lazarus subgroup, expanded its Contagious Interview-style developer targeting beyond cryptocurrency victims, weaponizing .terraform.lock.hcl files to redirect terraform init to typosquatted registries such as registry.hashicorp-aws[.]com and registry.hashicorp-terraform[.]io. An India-based IT services provider was infected with FLATROOF (macOS.Gaslight) and ROOFDECK implants observed on disk from March 18, 2026, on an Apple Silicon MacBook administered by a DevOps engineer managing AWS, OVH and OpenStack infrastructure. FLATROOF persists via a LaunchAgents plist, removes the quarantine attribute to bypass Gatekeeper, and collects keychain, browser, and command history data, exfiltrating via Telegram, while ROOFDECK resolves C2 through Nostr relays as a dead-drop mechanism. The same implants were tied to the April 2026 KelpDAO rsETH bridge attack via LayerZero, in which 116,500 rsETH (~$292 million) was stolen, with attribution by LayerZero, Mandiant, and CrowdStrike.
- Weaponized .terraform.lock.hcl files redirect terraform init to typosquatted registries delivering attacker-controlled provider code.
- FLATROOF achieves LaunchAgent persistence, bypasses Gatekeeper via quarantine removal, and exfiltrates data through Telegram.
- ROOFDECK uses Nostr profiles and relays as a dead-drop resolver to hide command-and-control infrastructure.
- Implants activated only during active Cursor sessions, quieting when the development environment was closed to evade detection.
- Same implants were used in the April 2026 KelpDAO-LayerZero incident involving theft of 116,500 rsETH worth ~$292M.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | grenight.com | CK binaries. The newer payload continued communicating with grenight[.]com until June 1. The same malware families were previously d |
| domain | hashicorp-aws.com | n typosquatted attacker infrastructure, including: registry.hashicorp-aws[.]com , registry.hashicorp-aws[.]io , and registry.hashicorp-te |
| domain | hashicorp-aws.io | ructure, including: registry.hashicorp-aws[.]com , registry.hashicorp-aws[.]io , and registry.hashicorp-terraform[.]io . When a victim e |
| domain | hashicorp-terraform.io | corp-aws[.]com , registry.hashicorp-aws[.]io , and registry.hashicorp-terraform[.]io . When a victim executes terraform init , Terraform uses |
| domain | hubpage.cloud | w) Domain technicais.sytes[.]net FLATROOF C2 Domain storage.hubpage[.]cloud ROOFDECK C2 Domain grenight[.]com ROOFDECK C2 IP 176.97.1 |
| domain | sytes.net | a06e767a2 Stripped ROOFDECK (loginwindow) Domain technicais.sytes[.]net FLATROOF C2 Domain storage.hubpage[.]cloud ROOFDECK C2 Do |
Full article912 words · extracted from gbhackers.com · click to collapse
North Korea-linked threat actor TraderTraitor has expanded its developer-focused intrusion activity beyond cryptocurrency targets, using weaponized Terraform lock files in fake job-interview repositories to infect DevOps engineers with macOS backdoors.
SentinelOne identified an Indian IT services provider compromised with the same FLATROOF and ROOFDECK implants previously linked to the April 2026 KelpDAO-LayerZero attack.
The campaign demonstrates how a seemingly routine infrastructure-as-code assignment can become an initial-access vector for cloud environments.
Instead of exploiting a Terraform vulnerability, the attackers abused trusted developer workflows by embedding malicious provider references inside .terraform.lock.hcl files, causing Terraform to retrieve attacker-controlled code when victims initialize the project.
In this activity, attackers contacted job seekers with fake interview tasks hosted on GitHub, a technique widely associated with the “Contagious Interview” campaign cluster.
The repositories masqueraded as infrastructure engineering projects, with names including Northwind-IAC, novacart-interview and terraform-candidate-repo.
The targets were DevOps, cloud and FinTech engineers individuals likely to have access to AWS, Google Cloud, source-control services, API keys and deployment pipelines.
SentinelOne noted that the real value of a compromised developer laptop is ultimately determined by the systems, credentials and cloud accounts it can reach.

The malicious repositories contained a weaponized .terraform.lock.hcl file specifying a custom provider source hosted on typosquatted attacker infrastructure, including:
registry.hashicorp-aws[.]com, registry.hashicorp-aws[.]io, and registry.hashicorp-terraform[.]io.
When a victim executes terraform init, Terraform uses the locked provider reference as the expected dependency source.
That workflow can lead to the download and execution of a malicious provider module supplied from the attacker-controlled registry, converting a normal coding exercise into a malware-delivery mechanism.
The newly identified victim was an India-based IT services organization with no apparent cryptocurrency connection.
The compromised endpoint was an Apple Silicon MacBook used by a DevOps engineer who regularly administered AWS, OVH and OpenStack infrastructure.
SentinelOne telemetry showed FLATROOF and ROOFDECK on disk from March 18, 2026, although researchers could not conclusively establish the original delivery point.
The malware remained inactive until March 29, when the engineer opened a cloudshield workspace in the Cursor development environment.
Seconds later, Cursor-launched processes started both implants, masquerading as SystemUpdate and iSync.
The malware’s operational behavior was selective. Beaconing activity was associated with active Cursor sessions and became quiet when Cursor was not running, a tactic that reduces the chance of detection outside normal development activity.
On April 13, the developer cloned a separate terraform-candidate-repo lure using GitHub Desktop, underlining the breadth of the social-engineering operation.
SentinelOne Researchers said that, TraderTraitor, also tracked as UNC4899, Jade Sleet and PUKCHONG, is a financially motivated DPRK-aligned Lazarus subgroup known for social-engineering software developers and cryptocurrency employees.
Terraform Lock Files
FLATROOF, also known as macOS.Gaslight, is a Rust-based ARM64 backdoor used for initial collection and secondary-payload deployment.
Persistence was achieved via a plist entry ~/Library/LaunchAgents/loginwindow.plist, with a dynamically specified application identifier string.
It can run shell commands, exfiltrate files through Telegram and collect browser data, command histories, installed applications, process listings, system details and copies of the macOS login keychain.

It also removes the com.apple.quarantine attribute from ROOFDECK and marks the second-stage implant executable, bypassing a key macOS Gatekeeper control without requiring a user prompt.
ROOFDECK provides broader post-compromise capabilities, including interactive and reverse shells, arbitrary command execution, file transfers, host reconnaissance, clipboard access, encrypted archive creation and persistence through LaunchAgents.
It uses Nostr profiles and relays as a dead-drop mechanism to resolve command-and-control infrastructure, complicating network-based blocking and attribution.
On April 20 one day after LayerZero publicly disclosed the KelpDAO incident the attackers deployed a stripped third-stage ROOFDECK variant named loginwindow, then deleted the original FLATROOF and ROOFDECK binaries.
The newer payload continued communicating with grenight[.]com until June 1.
The same malware families were previously deployed against a LayerZero Labs developer, who was socially engineered into cloning a malicious GitHub repository on March 6.
Attackers subsequently accessed the organization’s RPC cloud environment and poisoned infrastructure supporting the LayerZero Decentralized Verifier Network.
On April 18, the KelpDAO rsETH bridge attack resulted in the theft of 116,500 rsETH, valued at approximately $292 million at the time.
LayerZero, Mandiant and CrowdStrike linked the operation to TraderTraitor with varying levels of confidence.
The latest findings show that TraderTraitor is not limiting its operations to direct cryptocurrency targets.
DevOps engineers, cloud administrators and infrastructure developers are becoming strategic entry points because their workstations often hold the credentials and tooling needed to reach high-value production systems.
Organizations should treat third-party coding exercises as untrusted software, inspect .terraform.lock.hcl and provider source addresses before initialization.
Restrict provider installation to approved registries, and monitor developer endpoints for unexpected LaunchAgents, quarantine-attribute removal, and suspicious Terraform provider downloads.
IOCs
| Type | IOC | What it is |
| SHA1 | 02df07a173ab03b82a4fb6a08973fff8b1467f28 | FLATROOF (SystemUpdate) |
| SHA1 | c491d477dbe0ae04e9aed9dbe237144c03f73ec4 | ROOFDECK (iSync) |
| SHA1 | 5728b11d30586bbfc1d8bd12df1c722a06e767a2 | Stripped ROOFDECK (loginwindow) |
| Domain | technicais.sytes[.]net | FLATROOF C2 |
| Domain | storage.hubpage[.]cloud | ROOFDECK C2 |
| Domain | grenight[.]com | ROOFDECK C2 |
| IP | 176.97.114[.]232 | FLATROOF C2 (technicais.sytes[.]net) |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.