North Korea-linked hackers TraderTraitor expand attack targets beyond the crypto industry, using malicious Terraform projects to launch phishing attacks
Odaily reports that the North Korea-linked threat group TraderTraitor, also known as UNC4899 and Jade Sleet, recently breached an IT services company based in India that is unrelated to the crypto industry. The attackers posted fake job listings on GitHub, using technical interview assignments as bait to carry out phishing attacks targeting DevOps and crypto engineers.
After victims download the project, a malicious .terraform.lock.hcl file points to a Terraform Provider domain controlled by the attackers. Upon running terraform init, the malicious Provider module is downloaded and executed, ultimately deploying the Rust/ARM64 backdoors FLATROOF and ROOFDECK on macOS devices. The associated malware can steal credentials and sensitive data, execute shell commands, collect and exfiltrate files, and gain access to cloud services and code repositories.
