BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

North Korea-linked hackers TraderTraitor expand attack targets beyond the crypto industry, using malicious Terraform projects to launch phishing attacks

Odaily reports that the North Korea-linked threat group TraderTraitor, also known as UNC4899 and Jade Sleet, recently breached an IT services company based in India that is unrelated to the crypto industry. The attackers posted fake job listings on GitHub, using technical interview assignments as bait to carry out phishing attacks targeting DevOps and crypto engineers.

After victims download the project, a malicious .terraform.lock.hcl file points to a Terraform Provider domain controlled by the attackers. Upon running terraform init, the malicious Provider module is downloaded and executed, ultimately deploying the Rust/ARM64 backdoors FLATROOF and ROOFDECK on macOS devices. The associated malware can steal credentials and sensitive data, execute shell commands, collect and exfiltrate files, and gain access to cloud services and code repositories.