TraderTraitor Mac Malware Targets IT Firm Through Weaponized Terraform Projects

 

A North Korean-linked cybercrime group known as TraderTraitor has tied another macOS infection in an IT services company with no cryptocurrency ties to the exploitation of fake job interviews to gain access to developer systems.

The second victim, which has been identified as an India-based IT services provider, was targeted through one of the employees’ Apple Silicon MacBook belonging to a DevOps engineer. 
The compromised machine was used to manage AWS, OVH and OpenStack environments with the help of Terraform and Ansible, while the account also held cloud credentials and source code access.

SentinelOne attributed the breach to the same FLATROOF and ROOFDECK macOS backdoors employed by TraderTraitor in the attack targeting LayerZero Labs that resulted in the $292 million heist from crypto project KelpDAO. Initially detected on March 18 the malicious implants remained undetected until March 29, when they were triggered by the victim launching a workspace within the Cursor development environment. 
FLATROOF implant, which has been dropped as SystemUpdate, can be used to execute arbitrary shell commands, terminate processes and steal data. Its capabilities also include harvesting browser information, terminal history, installed applications, running processes, system properties and the macOS login keychain database.

ROOFDECK, which was deployed as iSync utility, allows for full command and control over the compromised system while also facilitating reverse shell access, file transfer exfiltration of data, reconnaissance, and persistent access through the use of LaunchAgents. 
It also has the capability to read the clipboard content, which may also contain passwords, cryptocurrency seed phrases and two-factor authentication (2FA) credentials.

On April 20, which came shortly after the public disclosure of the LayerZero breach, the threat actors deployed a modified version of ROOFDECK while removing the initial implants. The new sample continued to communicate with the C2 infrastructure controlled by the attacker until June 1.

“The incident serves as a stark reminder that developer endpoints must always be protected and monitored for suspicious activity,” the report noted. 
“These machines can serve as a gateway to cloud infrastructure, source code and deployment resources, which makes them attractive targets even for organizations with no direct involvement in crypto operations.”

It added that organizations should carefully monitor developer workstations for anomalous behaviors, including the launch of unsigned binary from the home directory, processes spawned by the development environments, and unusual network connections. 
It also recommended conducting regular audits of the Terraform lock files and make sure that the providers listed in them are legitimate before launching unfamiliar coding assignments or repositories.

This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents

Read the original article: