Register and share your invite link to earn from video plays and referrals.

SlowMist
@SlowMist_Team
SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.
Joined April 2018
410 Following    89.8K Followers
๐ŸšจSlowMist TI Alert: TraderTraitor Resurfaces via Weaponized Terraform Projects๐Ÿšจ DPRK-aligned threat actor #TraderTraitor# (aka UNC4899, Jade Sleet) โ€” previously behind the April 2026 LayerZero/KelpDAO breach (~$292M stolen) has compromised a new victim: an India-based IT services company with no ties to crypto. โš ๏ธ Attack chain: ๐ŸŽฏ Fake job interview lures target DevOps/crypto engineers on GitHub ๐Ÿ“ฆ Weaponized .terraform.lock.hcl files point to attacker-controlled Terraform provider domains โš™๏ธ Running terraform init triggers download & execution of malicious provider modules ๐Ÿ’ป Deploys two macOS backdoors (Rust/ARM64): FLATROOF & ROOFDECK โ€” same families used in the LayerZero attack ๐Ÿ”‘ Capabilities include: โ€ข Credential and sensitive data theft โ€ข Shell and command execution โ€ข File collection and exfiltration โ€ข Cloud and source-control access ๐Ÿ“Œ This shows TraderTraitor is casting a wider net โ€” even orgs with zero crypto exposure are being targeted, likely for whatever cloud/API access their developers can reach (AWS, GCP, OVH, OpenStack). ๐Ÿ›ก๏ธ Recommendations: ๐Ÿ‘‰ Treat unknown Terraform provider registries as suspect โ€” verify against ๐Ÿ‘‰ Flag engineers with cloud/source-control access for enhanced endpoint monitoring. ๐Ÿ‘‰ Be wary of unsolicited coding "interview assignments" and repos from recruiters. ๐Ÿ‘‰ Avoid using personal/corporate dev workstations for external job interviews. ๐Ÿ”Ž Source: @LabsSentinel
Show more