North Korean Hackers Use Fake Terraform Jobs to Deploy macOS Backdoors
Key Takeaways North Korean threat actors, specifically the TraderTraitor subgroup of Lazarus, are targeting macOS developers with fake Terraform job tests. The campaign aims to implant sophisticated...
Key Takeaways
- North Korean threat actors, specifically the TraderTraitor subgroup of Lazarus, are targeting macOS developers with fake Terraform job tests.
- The campaign aims to implant sophisticated backdoors, FLATROOF and ROOFDECK, onto developer machines.
- These backdoors enable data theft, remote control, and privilege escalation into cloud environments like AWS and Google Cloud Platform.
- The attack exploits trust in recruitment processes and leverages manipulated Terraform lock files to deliver malicious provider modules.
- Organizations and developers must exercise extreme caution with unsolicited coding assignments and rigorously verify all Terraform providers.
North Korean state-sponsored hackers are employing a sophisticated new tactic, using fabricated Terraform job tests to infiltrate macOS developer systems and gain access to critical cloud infrastructure. This campaign highlights a growing trend where seemingly innocuous technical assessments become conduits for data exfiltration, remote command execution, and deep network compromise by the financially motivated Lazarus subgroup, known as TraderTraitor (also tracked as UNC4899, PUKCHONG, and Jade Sleet).
Table Of Content
This activity follows a significant breach involving LayerZero and has also impacted an unrelated Indian IT services provider, demonstrating the group’s broadening scope beyond its traditional cryptocurrency targets. SentinelLABS said in a report that the attackers are now actively pursuing developers and cloud administrators, individuals who possess high-value technical access that can serve as a bridge into corporate networks.
The inherent risk is not confined to a specific employer or sector. A developer’s laptop often contains a treasure trove of sensitive credentials, including cloud access keys, source-code repository access, deployment permissions, and API keys. This makes such machines prime targets for adversaries seeking to establish a foothold within an organization’s digital ecosystem. This method mirrors other recruiter-themed traps previously observed in Lazarus Group campaigns, where the perceived legitimacy of a hiring process is exploited as the initial point of compromise.
North Korean TraderTraitor Hackers Use Fake Terraform Job Tests
TraderTraitor initiated contact with potential victims through infrastructure-focused interview assignments hosted on GitHub. The targets were carefully selected based on their public profiles, which typically indicated expertise in DevOps, cryptocurrency, or financial technology. This allowed the attackers to craft bespoke projects that appeared highly relevant to the candidates’ professional skills.
Researchers identified several malicious GitHub repositories, including those named Northwind-IAC, novacart-interview, and terraform-candidate-repo. Each of these deceptive lures contained a tampered `.terraform.lock.hcl` file. This file was designed to redirect Terraform to an attacker-controlled provider registry instead of a legitimate one. Consequently, executing the `terraform init` command would inadvertently download and run malicious provider modules, initiating the infection chain.
The effectiveness of this tactic lies in the subtle nature of lock files, which are often perceived as standard project metadata. One alert candidate reportedly detected an anomalous provider and promptly removed it, underscoring that diligent review can prevent an infection before any malicious code is executed. This concern echoes previous incidents involving malicious Terraform registry attacks, which highlighted the inherent dangers of compromised infrastructure packages. Once access was established, the operators deployed the FLATROOF and ROOFDECK backdoors onto macOS systems. In the earlier LayerZero intrusion, these tools were instrumental in collecting API keys and facilitating privilege escalation within Amazon Web Services (AWS) and Google Cloud Platform (GCP) environments. This strategy targets both the compromised endpoint and its associated cloud access.
macOS Implants Expand Control
At the Indian IT services company, the attackers successfully compromised an Apple Silicon MacBook belonging to a DevOps engineer. This machine, which regularly managed AWS, OVH, and OpenStack resources, contained critical cloud credentials and source-control access. Telemetry data indicated that both FLATROOF and ROOFDECK implants were present on the disk by March 18, with malicious activity commencing on March 29.
FLATROOF, disguised as “SystemUpdate,” was engineered for initial data collection and subsequent payload delivery. Its capabilities include executing shell commands, exfiltrating files via Telegram, harvesting browser data and terminal histories, listing installed applications, recording active processes, profiling the system, and copying the login keychain. Its operational characteristics are consistent with findings from previous investigations into Rust-based macOS backdoors known for their data-stealing capabilities.
ROOFDECK, which masqueraded as “iSync,” provided the attackers with a more extensive range of control. This backdoor can search for valuable files, execute arbitrary commands, create encrypted archives, transfer data, read clipboard contents, and establish persistence through a LaunchAgent. Notably, it resolves its command-and-control (C2) servers via the decentralized Nostr network, enhancing the flexibility and resilience of its communications.
Later, the attackers deployed a streamlined variant of ROOFDECK, named “loginwindow,” subsequently removing the initial implants. This new variant continued to beacon until June 1. This operational shift suggests the group’s ability to adapt its tooling mid-intrusion and minimize forensic evidence on compromised devices. It also reflects the persistent nature observed in other developer-focused campaigns, such as North Korean Git hook malware distribution.
What You Should Do
- Treat all personnel with cloud and source-control privileges as a high-risk monitoring group.
- Actively monitor for unsigned applications running from user home directories and unusual child processes originating from development tools.
- Investigate any unexpected encrypted outbound network traffic from developer workstations.
- Exercise extreme caution with unsolicited interview assignments or coding challenge repositories, especially those from unfamiliar sources.
- Avoid opening or executing external assessment projects on corporate workstations.
- Thoroughly inspect every provider listed in a Terraform lock file (`.terraform.lock.hcl`) before running `terraform init`.
- Immediately scrutinize any Terraform provider names that do not reside within the official `registry.terraform.io` namespace.
- Even for packages from official registries, trace their origin to source code and verify the publisher’s legitimacy.
- Implement strong endpoint detection and response (EDR) solutions capable of detecting advanced persistent threats.
- Educate developers and IT staff on social engineering tactics and supply chain risks.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-1 | 02df07a173ab03b82a4fb6a08973fff8b1467f28 |
FLATROOF, masquerading as SystemUpdate |
| SHA-1 | c491d477dbe0ae04e9aed9dbe237144c03f73ec4 |
ROOFDECK, masquerading as iSync |
| SHA-1 | 5728b11d30586bbfc1d8bd12df1c722a06e767a2 |
Stripped ROOFDECK, masquerading as loginwindow |
| Domain | technicais.sytes[.]net |
FLATROOF command-and-control server |
| Domain | storage.hubpage[.]cloud |
ROOFDECK command-and-control server |
| Domain | grenight[.]com |
ROOFDECK command-and-control server |
| IP address | 176.97.114[.]232 |
FLATROOF C2 associated with technicais.sytes[.]net |
| IP address | 45.11.59[.]140 |
ROOFDECK C2 associated with storage.hubpage[.]cloud |
| IP address | 85.137.56[.]245 |
ROOFDECK C2 associated with grenight[.]com |
| IP address | 85.137.56[.]10 |
ROOFDECK staging server |
| File path | ~/Library/com.apple.iTunesCloud/SystemUpdate |
FLATROOF binary path |
| File path | ~/Library/com.apple.internal.ck/iSync |
ROOFDECK binary path |
| File path | ~/Library/com.apple.appleaccountd/loginwindow |
Stripped ROOFDECK binary path |
| File | /private/tmp/.pipe-airway |
ROOFDECK inter-process communication pipe |
| File | $TMPDIR/tmp*.lock |
FLATROOF lock file |
| Workspace | ~/DevOps-Automation/cloudshield |
Malicious workspace path |
| TLS certificate SHA-256 | 4b2d3e8ccce8920a6d01e7d02b84236545a20e5f754b3eec253f8b416b731daa |
Custom certificate used for TLS communication |
| TLS certificate SHA-1 | 4ad92bf92ee614b05c340ce17bef7b6ef5a25e82 |
Custom certificate used for TLS communication |
| TLS certificate serial | 1cd6d13ff15adbf7a42025d10ec99b4a |
Custom certificate serial number |
| TLS certificate subject/issuer | O=mkcert development CA, OU=ub@ub-Standard-PC-Q35-ICH9-2009, CN=mkcert ub@ub-Standard-PC-Q35-ICH9-2009 |
Self-signed ROOFDECK TLS certificate metadata |
| Persistence | ~/Library/LaunchAgents/*.plist |
Label starts with com., ProgramArguments includes --type=renderer, and RunAtLoad=true |
| Configuration file | $HOME/.config/.repl_history |
ROOFDECK configuration file |
| HTTPS endpoint | /app_version |
ROOFDECK tasking endpoint, with host resolved at runtime |
| Domain | 185-66-91-112.cprapid[.]com |
Domain associated with the ub certificate user |
| Domain | 213-111-146-132.cprapid[.]com |
Domain associated with the ub certificate user |
| Domain | anesthesiaschool[.]com |
Domain associated with the ub certificate user |
| Domain | app.heyhay[.]online |
Domain associated with the ub certificate user |
| Domain | dela.servehttp[.]com |
Domain associated with the ub certificate user |
| Domain | galaxy-royal[.]online |
Domain associated with the ub certificate user |
| Domain | game.galaxy-royal[.]online |
Domain associated with the ub certificate user |
| Domain | heyhay[.]online |
Domain associated with the ub certificate user |
| Domain | mactroubleshoots[.]pro |
Domain associated with the ub certificate user |
| Domain | mx01.galaxy-royal[.]online |
Domain associated with the ub certificate user |
| Domain | ns4.galaxy-royal[.]online |
Domain associated with the ub certificate user |
| Domain | tinklify[.]com |
Domain associated with the ub certificate user |
| Domain | update.heyhay[.]online |
Domain associated with the ub certificate user |
| Domain | vaimage[.]com |
Domain associated with the ub certificate user |
| Domain | wss.sytes[.]net |
Domain associated with the ub certificate user |
| Domain | www.anesthesiaschool[.]com |
Domain associated with the ub certificate user |
| Domain | www.freehealth[.]lat |
Domain associated with the ub certificate user |
| Domain | www.heyhay[.]online |
Domain associated with the ub certificate user |
| Domain | www.mactroubleshoots[.]pro |
Domain associated with the ub certificate user |
| Domain | www.tinklify[.]com |
Domain associated with the ub certificate user |
| Malicious provider domain | registry.hashicorp-aws[.]com |
Typosquatted Terraform provider domain used in weaponized repositories |
| Malicious provider domain | registry.hashicorp-aws[.]io |
Typosquatted Terraform provider domain used in weaponized repositories |
| Malicious provider domain | registry.hashicorp-terraform[.]io |
Typosquatted Terraform provider domain used in weaponized repositories |
| GitHub repository | github[.]com/exubient0/terraform-candidate-repo |
Repository containing a weaponized Terraform lock file |
| GitHub repository | github[.]com/radupopa369/gtn-candidate-repo |
Repository containing a weaponized Terraform lock file |
| GitHub repository | github[.]com/chainstacker/Northwind-IAC |
Repository associated with the hashicorp-aws[.]io provider lure |
| GitHub repository | github[.]com/RyanLRay/Technical-Assessments |
Repository README referencing the weaponized provider domain |
| GitHub repository | github[.]com/Steed-LHV/assessment |
Repository README referencing the hashicorp-terraform[.]io provider domain |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.