Trojanized Terraform Provider Linked to FLATROOF and ROOFDECK
Researchers say a July 2026 trojanized Terraform AWS provider delivers cross-platform FLATROOF malware, with ROOFDECK also reported and TraderTraitor attribution unconfirmed.
Zscaler ThreatLabz analyzed terraform-provider-awsbeta_v1.0.0, a Go binary that masquerades as an AWS provider for HashiCorp Terraform and executes attacker code when Terraform loads it. GBHackers and Cyber Security News place the activity in July 2026. The provider retrieves a Bash loader, named safari_updater by Cyber Security News, from hashicorp-terraform.io; that loader then obtains AES-encrypted, OS-specific payloads disguised as font files, which Zscaler says come from dynamic DNS, GitHub, and Vercel, while Cyber Security News says they follow decoy data in .woff files and are Base64-decoded and AES-256-CBC decrypted. The resulting Rust backdoor, assessed as FLATROOF, targets Linux, macOS, and Windows, uses Telegram, HTTPS, and GitHub polling, and persists through a Linux service, macOS zlogout, or the Windows registry. Secondary outlets also describe browser, keychain, Windows credential, and crypto-wallet theft and say the campaign installs ROOFDECK, which can open shells, transfer files, access the clipboard, and locate servers through Pastebin or Nostr, whereas Zscaler centers on FLATROOF and says SentinelLabs separately reported related FLATROOF and ROOFDECK activity. Attribution is only suspected TraderTraitor overlap—aliases include Jade Sleet, UNC4899, Pressure Chollima, and Slow Pisces—without high confidence; initial distribution remains unknown, and the related incident is called KalpDAO by Zscaler but KelpDAO, plus an Indian IT-services compromise, by GBHackers.
- Zscaler ThreatLabz analyzed terraform-provider-awsbeta_v1.0.0, a Go binary posing as an AWS Terraform provider that runs attacker code when Terraform loads it; GBHackers and Cyber Security News date the campaign to July 2026.
- The provider downloads a Bash loader from hashicorp-terraform.io; Cyber Security News names that loader safari_updater.
- The loader fetches OS-specific AES-encrypted payloads disguised as font files. Zscaler cites dynamic DNS, GitHub, and Vercel, while Cyber Security News says payloads sit after decoy data in .woff files and are Base64-decoded and…
- The decrypted Rust backdoor is assessed as FLATROOF, targets Linux, macOS, and Windows, uses Telegram, HTTPS, and GitHub polling, and persists via a Linux service, macOS zlogout, or the Windows registry.
- Secondary reports say FLATROOF steals browser, keychain, Windows credential, and cryptocurrency-wallet data and that the same campaign installs ROOFDECK, which supports shells, file transfer, clipboard access, and command-and-control…
- Researchers note overlap with suspected TraderTraitor, also tracked as Jade Sleet, UNC4899, Pressure Chollima, and Slow Pisces, but say attribution is not high confidence. How the provider was first distributed remains unknown.
- Related incident naming differs: Zscaler refers to KalpDAO, while GBHackers refers to a KelpDAO bridge theft and an Indian IT-services compromise.
Coverage timelineoldest first · each row is one article
- · 1d agoSuspected TraderTraitor Group Uses Trojanized Terraform Provider to Deliver Cross-Platform Malware
Zscaler ThreatLabz· 72
Suspected TraderTraitor operators trojanized a Terraform provider to deliver the cross-platform FLATROOF backdoor.
- · 1d agoSuspected TraderTraitor Hackers Trojanize Terraform Provider to Deploy Cross-Platform Malware
GBHackers· 76
Suspected North Korean hackers trojanized a Terraform provider to install FLATROOF and ROOFDECK on developer machines.
- · 1d ago