North Korean TraderTraitor Hackers Use Fake Terraform Job Tests to Deploy macOS Backdoors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


North Korean threat actors are using fake Terraform job tests to compromise macOS developers and reach cloud systems. The campaign shows how a routine coding assignment can become an entry point for data theft, remote control, and deeper network intrusion.

The activity is tied to TraderTraitor, a financially motivated Lazarus subgroup also tracked as UNC4899, PUKCHONG, and Jade Sleet.

It follows a major incident involving LayerZero, and investigators found an unrelated Indian IT services provider affected by the backdoors.

SentinelLABS said in a report shared with Cyber Security News (CSN) that the attackers expanded their focus beyond crypto firms.

The finding shows North Korean operators pursue developers, cloud administrators, and people who hold valuable technical access.

The risk is not limited to one employer or one industry. A developer laptop can hold cloud credentials, source-code access, deployment permissions, and application programming interface keys, making it a high-value bridge into corporate infrastructure.

Similar recruiter-led traps have appeared in recent Lazarus interview campaigns, where trust in a supposed hiring process becomes the initial weakness.

North Korean TraderTraitor Hackers Use Fake Terraform Job Tests

TraderTraitor approached job seekers with infrastructure-focused interview assignments hosted in GitHub repositories. The targets’ public profiles commonly showed DevOps, cryptocurrency, or financial-technology experience, allowing the operators to tailor projects that looked relevant to their professional skills.

Researchers identified repositories using names such as Northwind-IAC, novacart-interview, and terraform-candidate-repo.

Each lure contained a manipulated .terraform.lock.hcl file that directed Terraform toward an attacker-controlled provider registry instead of a legitimate source. Running terraform init then downloaded and executed malicious provider modules.

Interview task from a GitHub repository containing a weaponized .terraform.lock.hcl file (Source - SentinelLABS)
Interview task from a GitHub repository containing a weaponized .terraform.lock.hcl file (Source – SentinelLABS)

The tactic is particularly effective because lock files appear to be ordinary project metadata. One candidate noticed a suspicious lookalike provider and removed it, suggesting that careful review can stop an infection before code runs.

That concern echoes malicious Terraform registry attacks, which demonstrated the danger of compromised infrastructure packages. The operators used this access to install FLATROOF and ROOFDECK backdoors on macOS.

In the earlier LayerZero intrusion, the tools helped collect API keys and supported privilege escalation into Amazon Web Services and Google Cloud Platform environments. The campaign therefore targets both the endpoint and the cloud access connected to it.

macOS Implants Expand Control

At the Indian IT services victim, the attackers compromised an Apple Silicon MacBook used by a DevOps engineer. The machine routinely managed AWS, OVH, and OpenStack resources, holding cloud credentials and source-control access. Telemetry showed both implants on disk by March 18, before activity began on March 29.

FLATROOF was disguised as SystemUpdate and was designed for initial collection and follow-on delivery. It can run shell commands, upload files through Telegram, gather browser data and terminal histories, list installed applications, record running processes, profile the system, and copy the login keychain.

Its behavior aligns with the Rust macOS backdoor investigation, which documented its data-stealing capability. ROOFDECK, masquerading as iSync, offered broader control.

Weaponized .terraform.lock.hcl file (Source - SentinelLABS)
Weaponized .terraform.lock.hcl file (Source – SentinelLABS)

It can search for valuable files, execute commands, create encrypted archives, transfer data, read the clipboard, and establish persistence through a LaunchAgent. It also resolves command servers through the decentralized Nostr network, making its communications more flexible for operators.

The attackers later deployed a stripped ROOFDECK variant called loginwindow, removed the earlier implants, and continued beaconing through June 1.

This shift suggests that the group can refresh its tooling during an intrusion and reduce evidence left on the victim device. It also reflects the persistence seen when North Korean Git hooks spread malware, another developer-focused campaign.

Organizations should treat staff with cloud and source-control privileges as a sensitive monitoring group. Security teams should investigate unsigned programs launched from home directories, unusual child processes from development tools, unexpected encrypted outbound traffic, and unsolicited interview repositories.

Developers should avoid opening external assessments on corporate workstations and verify every provider in a Terraform lock file before running it.

Provider names that do not use the known registry.terraform.io namespace merit immediate scrutiny, while even packages from official registries should be traced to their source code and trusted publisher.

Indicators of compromise (IoCs):-

Type Indicator Description
SHA-1 02df07a173ab03b82a4fb6a08973fff8b1467f28 FLATROOF, masquerading as SystemUpdate
SHA-1 c491d477dbe0ae04e9aed9dbe237144c03f73ec4 ROOFDECK, masquerading as iSync
SHA-1 5728b11d30586bbfc1d8bd12df1c722a06e767a2 Stripped ROOFDECK, masquerading as loginwindow
Domain technicais.sytes[.]net FLATROOF command-and-control server
Domain storage.hubpage[.]cloud ROOFDECK command-and-control server
Domain grenight[.]com ROOFDECK command-and-control server
IP address 176.97.114[.]232 FLATROOF C2 associated with technicais.sytes[.]net
IP address 45.11.59[.]140 ROOFDECK C2 associated with storage.hubpage[.]cloud
IP address 85.137.56[.]245 ROOFDECK C2 associated with grenight[.]com
IP address 85.137.56[.]10 ROOFDECK staging server
File path ~/Library/com.apple.iTunesCloud/SystemUpdate FLATROOF binary path
File path ~/Library/com.apple.internal.ck/iSync ROOFDECK binary path
File path ~/Library/com.apple.appleaccountd/loginwindow Stripped ROOFDECK binary path
File /private/tmp/.pipe-airway ROOFDECK inter-process communication pipe
File $TMPDIR/tmp*.lock FLATROOF lock file
Workspace ~/DevOps-Automation/cloudshield Malicious workspace path
TLS certificate SHA-256 4b2d3e8ccce8920a6d01e7d02b84236545a20e5f754b3eec253f8b416b731daa Custom certificate used for TLS communication
TLS certificate SHA-1 4ad92bf92ee614b05c340ce17bef7b6ef5a25e82 Custom certificate used for TLS communication
TLS certificate serial 1cd6d13ff15adbf7a42025d10ec99b4a Custom certificate serial number
TLS certificate subject/issuer O=mkcert development CA, OU=ub@ub-Standard-PC-Q35-ICH9-2009, CN=mkcert ub@ub-Standard-PC-Q35-ICH9-2009 Self-signed ROOFDECK TLS certificate metadata
Persistence ~/Library/LaunchAgents/*.plist Label starts with com., ProgramArguments includes --type=renderer, and RunAtLoad=true
Configuration file $HOME/.config/.repl_history ROOFDECK configuration file
HTTPS endpoint /app_version ROOFDECK tasking endpoint, with host resolved at runtime
Domain 185-66-91-112.cprapid[.]com Domain associated with the ub certificate user
Domain 213-111-146-132.cprapid[.]com Domain associated with the ub certificate user
Domain anesthesiaschool[.]com Domain associated with the ub certificate user
Domain app.heyhay[.]online Domain associated with the ub certificate user
Domain dela.servehttp[.]com Domain associated with the ub certificate user
Domain galaxy-royal[.]online Domain associated with the ub certificate user
Domain game.galaxy-royal[.]online Domain associated with the ub certificate user
Domain heyhay[.]online Domain associated with the ub certificate user
Domain mactroubleshoots[.]pro Domain associated with the ub certificate user
Domain mx01.galaxy-royal[.]online Domain associated with the ub certificate user
Domain ns4.galaxy-royal[.]online Domain associated with the ub certificate user
Domain tinklify[.]com Domain associated with the ub certificate user
Domain update.heyhay[.]online Domain associated with the ub certificate user
Domain vaimage[.]com Domain associated with the ub certificate user
Domain wss.sytes[.]net Domain associated with the ub certificate user
Domain www.anesthesiaschool[.]com Domain associated with the ub certificate user
Domain www.freehealth[.]lat Domain associated with the ub certificate user
Domain www.heyhay[.]online Domain associated with the ub certificate user
Domain www.mactroubleshoots[.]pro Domain associated with the ub certificate user
Domain www.tinklify[.]com Domain associated with the ub certificate user
Malicious provider domain registry.hashicorp-aws[.]com Typosquatted Terraform provider domain used in weaponized repositories
Malicious provider domain registry.hashicorp-aws[.]io Typosquatted Terraform provider domain used in weaponized repositories
Malicious provider domain registry.hashicorp-terraform[.]io Typosquatted Terraform provider domain used in weaponized repositories
GitHub repository github[.]com/exubient0/terraform-candidate-repo Repository containing a weaponized Terraform lock file
GitHub repository github[.]com/radupopa369/gtn-candidate-repo Repository containing a weaponized Terraform lock file
GitHub repository github[.]com/chainstacker/Northwind-IAC Repository associated with the hashicorp-aws[.]io provider lure
GitHub repository github[.]com/RyanLRay/Technical-Assessments Repository README referencing the weaponized provider domain
GitHub repository github[.]com/Steed-LHV/assessment Repository README referencing the hashicorp-terraform[.]io provider domain

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post North Korean TraderTraitor Hackers Use Fake Terraform Job Tests to Deploy macOS Backdoors appeared first on Cyber Security News.