๐จSlowMist TI Alert: TraderTraitor Resurfaces via Weaponized Terraform Projects๐จ
DPRK-aligned threat actor #
TraderTraitor# (aka UNC4899, Jade Sleet) โ previously behind the April 2026 LayerZero/KelpDAO breach (~$292M stolen) has compromised a new victim: an India-based IT services company with no ties to crypto.
โ ๏ธ Attack chain:
๐ฏ Fake job interview lures target DevOps/crypto engineers on GitHub
๐ฆ Weaponized .terraform.lock.hcl files point to attacker-controlled Terraform provider domains
โ๏ธ Running terraform init triggers download & execution of malicious provider modules
๐ป Deploys two macOS backdoors (Rust/ARM64): FLATROOF & ROOFDECK โ same families used in the LayerZero attack
๐ Capabilities include:
โข Credential and sensitive data theft
โข Shell and command execution
โข File collection and exfiltration
โข Cloud and source-control access
๐ This shows TraderTraitor is casting a wider net โ even orgs with zero crypto exposure are being targeted, likely for whatever cloud/API access their developers can reach (AWS, GCP, OVH, OpenStack).
๐ก๏ธ Recommendations:
๐ Treat unknown Terraform provider registries as suspect โ verify against
๐ Flag engineers with cloud/source-control access for enhanced endpoint monitoring.
๐ Be wary of unsolicited coding "interview assignments" and repos from recruiters.
๐ Avoid using personal/corporate dev workstations for external job interviews.
๐ Source:
@LabsSentinel