IntroductionIn July 2026, Zscaler ThreatLabz uncovered a campaign linked to TraderTraitor (also tracked as Jade Sleet, UNC4899, Pressure Chollima, and Slow Pisces), an advanced persistent threat actor backed by the North Korean government that has targeted the cryptocurrency industry for years. This campaign also significantly overlaps with the previously reported KelpDAO incident, the analysis of which discussed both FLATROOF and ROOFDECK, two malware families also observed in this campaign. The attackers utilized a trojanized Terraform provider to deliver a Bash loader that selects and downloads malware tailored to the victim's operating system. The FLATROOF malware deployed Python scripts to steal sensitive data from the victim before ultimately dropping the ROOFDECK backdoor to gain full remote control.In this blog, ThreatLabz examines the inner workings of these tools and analyzes the multi-stage infection chain. We also explore how this sophisticated malware conceals and retrieves its final command-and-control (C2) address to evade detection. Key TakeawaysIn July 2026, ThreatLabz discovered a trojanized Terraform provider that executes malicious code as soon as Terraform loads the provider.The trojanized Terraform provider downloads a cross-platform Bash loader from a HashiCorp-themed lookalike domain while preserving normal Terraform behavior.The loader selects payloads for macOS, Linux, and Windows according to the operating system and CPU architecture.Encrypted executables are appended to decoy .woff files and recovered using marker-based extraction and AES-256-CBC decryption.The delivered FLATROOF variant is a Rust-based cross-platform backdoor with platform-specific persistence and redundant C2 channels.The FLATROOF Python stealers target browser credentials, cookies, terminal history, system information, and cryptocurrency wallet extensions.The subsequent backdoor named ROOFDECK uses layered C2 discovery through local configuration, a cryptographically signed Pastebin dead drop, and Nostr profile metadata. Attack ChainThe figure below illustrates the attack chain, from the execution of the trojanized Terraform provider through FLATROOF deployment, data theft, and installation of the ROOFDECK backdoors. Figure 1: Infection chain delivering FLATROOF and ROOFDECK through a trojanized Terraform provider. Technical AnalysisWhile this analysis was being prepared for publication, SentinelLabs independently reported related TraderTraitor activity involving weaponized Terraform projects, FLATROOF, and ROOFDECK malware. Their research provides detailed insight into the social engineering and initial intrusion aspects of the campaign. Our analysis focuses on the internal implementation of the malicious Terraform provider and its cross-platform payload delivery mechanism.Trojanized Terraform providerThe initial payload identified by ThreatLabz is written in Go and named terraform-provider-awsbeta_v1.0.0. It masquerades as an Amazon Web Services (AWS) provider for HashiCorp Terraform. Terraform providers are executable plugins loaded by Terraform to communicate with infrastructure platforms and services. Although it remains unclear how the trojanized Terraform provider was delivered to the victim, Terraform provider binaries execute on developer workstations and CI/CD systems. This suggests that the campaign may target cloud engineers or developers who use Terraform.The binary’s Go symbols reveal a functional provider scaffold under terraform-provider-awsbeta/internal/provider, including example resource and data source implementations. The threat actor added a malicious sibling package named awsbeta and called its exported routine directly from main. As a result, the malicious code executes when Terraform starts the provider.The provider uses a file named session.lock in the system temporary directory as a run-once marker. If the marker is absent, the provider:Determines the temporary directory using TMPDIR, falling back to /tmp.Downloads a second-stage payload over HTTPS.Writes a Bash payload to a file named safari_updater in the temporary directory.Adds executable permissions to the file.Launches it through sh -c as a detached child process.Creates the lock file to prevent repeated execution.The download URL uses the lookalike domain hashicorp-terraform[.]io and a path resembling a legitimate Terraform plugin metrics endpoint. Meanwhile, the provider continues to respond as expected, which may make the compromise less noticeable to the victim.Cross-platform Bash loaderThe downloaded safari_updater file is a Bash script that supports macOS, Linux, and Windows systems running a compatible Unix-like shell environment such as Cygwin, MinGW, or MSYS.The script maps each operating system to a font family and each architecture to a font style to construct the filename for the next-stage payload. Linux uses NotoSansCJK, macOS uses HiraginoSans, and Windows uses the MalgunGothic font name for the next-stage
[…]
Content was trimmed to protect the source. Please visit the original article for the full text.
This article has been indexed from Security Research | Blog
Read the original article:
Related