Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Payload Ransomware Abuses Group Policy to Disrupt Windows Domains
September 21, 2026
Malicious npm Package Hides Malware in Runtime Code
September 21, 2026
North Korea’s Hangro VPN Infrastructure Exposed by TLS Certificate Leak
September 21, 2026
Home/Threats/North Korean Hackers Use Fake Terraform Jobs to Deploy macOS Backdoors
Threats

North Korean Hackers Use Fake Terraform Jobs to Deploy macOS Backdoors

Key Takeaways North Korean threat actors, specifically the TraderTraitor subgroup of Lazarus, are targeting macOS developers with fake Terraform job tests. The campaign aims to implant sophisticated...

Emy Elsamnoudy
Emy Elsamnoudy
September 21, 2026 6 Min Read
3 0

Key Takeaways

  • North Korean threat actors, specifically the TraderTraitor subgroup of Lazarus, are targeting macOS developers with fake Terraform job tests.
  • The campaign aims to implant sophisticated backdoors, FLATROOF and ROOFDECK, onto developer machines.
  • These backdoors enable data theft, remote control, and privilege escalation into cloud environments like AWS and Google Cloud Platform.
  • The attack exploits trust in recruitment processes and leverages manipulated Terraform lock files to deliver malicious provider modules.
  • Organizations and developers must exercise extreme caution with unsolicited coding assignments and rigorously verify all Terraform providers.

North Korean state-sponsored hackers are employing a sophisticated new tactic, using fabricated Terraform job tests to infiltrate macOS developer systems and gain access to critical cloud infrastructure. This campaign highlights a growing trend where seemingly innocuous technical assessments become conduits for data exfiltration, remote command execution, and deep network compromise by the financially motivated Lazarus subgroup, known as TraderTraitor (also tracked as UNC4899, PUKCHONG, and Jade Sleet).

Table Of Content

  • Key Takeaways
  • North Korean TraderTraitor Hackers Use Fake Terraform Job Tests
  • macOS Implants Expand Control
  • What You Should Do

This activity follows a significant breach involving LayerZero and has also impacted an unrelated Indian IT services provider, demonstrating the group’s broadening scope beyond its traditional cryptocurrency targets. SentinelLABS said in a report that the attackers are now actively pursuing developers and cloud administrators, individuals who possess high-value technical access that can serve as a bridge into corporate networks.

The inherent risk is not confined to a specific employer or sector. A developer’s laptop often contains a treasure trove of sensitive credentials, including cloud access keys, source-code repository access, deployment permissions, and API keys. This makes such machines prime targets for adversaries seeking to establish a foothold within an organization’s digital ecosystem. This method mirrors other recruiter-themed traps previously observed in Lazarus Group campaigns, where the perceived legitimacy of a hiring process is exploited as the initial point of compromise.

North Korean TraderTraitor Hackers Use Fake Terraform Job Tests

TraderTraitor initiated contact with potential victims through infrastructure-focused interview assignments hosted on GitHub. The targets were carefully selected based on their public profiles, which typically indicated expertise in DevOps, cryptocurrency, or financial technology. This allowed the attackers to craft bespoke projects that appeared highly relevant to the candidates’ professional skills.

Researchers identified several malicious GitHub repositories, including those named Northwind-IAC, novacart-interview, and terraform-candidate-repo. Each of these deceptive lures contained a tampered `.terraform.lock.hcl` file. This file was designed to redirect Terraform to an attacker-controlled provider registry instead of a legitimate one. Consequently, executing the `terraform init` command would inadvertently download and run malicious provider modules, initiating the infection chain.

The effectiveness of this tactic lies in the subtle nature of lock files, which are often perceived as standard project metadata. One alert candidate reportedly detected an anomalous provider and promptly removed it, underscoring that diligent review can prevent an infection before any malicious code is executed. This concern echoes previous incidents involving malicious Terraform registry attacks, which highlighted the inherent dangers of compromised infrastructure packages. Once access was established, the operators deployed the FLATROOF and ROOFDECK backdoors onto macOS systems. In the earlier LayerZero intrusion, these tools were instrumental in collecting API keys and facilitating privilege escalation within Amazon Web Services (AWS) and Google Cloud Platform (GCP) environments. This strategy targets both the compromised endpoint and its associated cloud access.

macOS Implants Expand Control

At the Indian IT services company, the attackers successfully compromised an Apple Silicon MacBook belonging to a DevOps engineer. This machine, which regularly managed AWS, OVH, and OpenStack resources, contained critical cloud credentials and source-control access. Telemetry data indicated that both FLATROOF and ROOFDECK implants were present on the disk by March 18, with malicious activity commencing on March 29.

FLATROOF, disguised as “SystemUpdate,” was engineered for initial data collection and subsequent payload delivery. Its capabilities include executing shell commands, exfiltrating files via Telegram, harvesting browser data and terminal histories, listing installed applications, recording active processes, profiling the system, and copying the login keychain. Its operational characteristics are consistent with findings from previous investigations into Rust-based macOS backdoors known for their data-stealing capabilities.

ROOFDECK, which masqueraded as “iSync,” provided the attackers with a more extensive range of control. This backdoor can search for valuable files, execute arbitrary commands, create encrypted archives, transfer data, read clipboard contents, and establish persistence through a LaunchAgent. Notably, it resolves its command-and-control (C2) servers via the decentralized Nostr network, enhancing the flexibility and resilience of its communications.

Later, the attackers deployed a streamlined variant of ROOFDECK, named “loginwindow,” subsequently removing the initial implants. This new variant continued to beacon until June 1. This operational shift suggests the group’s ability to adapt its tooling mid-intrusion and minimize forensic evidence on compromised devices. It also reflects the persistent nature observed in other developer-focused campaigns, such as North Korean Git hook malware distribution.

What You Should Do

  • Treat all personnel with cloud and source-control privileges as a high-risk monitoring group.
  • Actively monitor for unsigned applications running from user home directories and unusual child processes originating from development tools.
  • Investigate any unexpected encrypted outbound network traffic from developer workstations.
  • Exercise extreme caution with unsolicited interview assignments or coding challenge repositories, especially those from unfamiliar sources.
  • Avoid opening or executing external assessment projects on corporate workstations.
  • Thoroughly inspect every provider listed in a Terraform lock file (`.terraform.lock.hcl`) before running `terraform init`.
  • Immediately scrutinize any Terraform provider names that do not reside within the official `registry.terraform.io` namespace.
  • Even for packages from official registries, trace their origin to source code and verify the publisher’s legitimacy.
  • Implement strong endpoint detection and response (EDR) solutions capable of detecting advanced persistent threats.
  • Educate developers and IT staff on social engineering tactics and supply chain risks.

Indicators of Compromise (IoCs):-

Type Indicator Description
SHA-1 02df07a173ab03b82a4fb6a08973fff8b1467f28 FLATROOF, masquerading as SystemUpdate
SHA-1 c491d477dbe0ae04e9aed9dbe237144c03f73ec4 ROOFDECK, masquerading as iSync
SHA-1 5728b11d30586bbfc1d8bd12df1c722a06e767a2 Stripped ROOFDECK, masquerading as loginwindow
Domain technicais.sytes[.]net FLATROOF command-and-control server
Domain storage.hubpage[.]cloud ROOFDECK command-and-control server
Domain grenight[.]com ROOFDECK command-and-control server
IP address 176.97.114[.]232 FLATROOF C2 associated with technicais.sytes[.]net
IP address 45.11.59[.]140 ROOFDECK C2 associated with storage.hubpage[.]cloud
IP address 85.137.56[.]245 ROOFDECK C2 associated with grenight[.]com
IP address 85.137.56[.]10 ROOFDECK staging server
File path ~/Library/com.apple.iTunesCloud/SystemUpdate FLATROOF binary path
File path ~/Library/com.apple.internal.ck/iSync ROOFDECK binary path
File path ~/Library/com.apple.appleaccountd/loginwindow Stripped ROOFDECK binary path
File /private/tmp/.pipe-airway ROOFDECK inter-process communication pipe
File $TMPDIR/tmp*.lock FLATROOF lock file
Workspace ~/DevOps-Automation/cloudshield Malicious workspace path
TLS certificate SHA-256 4b2d3e8ccce8920a6d01e7d02b84236545a20e5f754b3eec253f8b416b731daa Custom certificate used for TLS communication
TLS certificate SHA-1 4ad92bf92ee614b05c340ce17bef7b6ef5a25e82 Custom certificate used for TLS communication
TLS certificate serial 1cd6d13ff15adbf7a42025d10ec99b4a Custom certificate serial number
TLS certificate subject/issuer O=mkcert development CA, OU=ub@ub-Standard-PC-Q35-ICH9-2009, CN=mkcert ub@ub-Standard-PC-Q35-ICH9-2009 Self-signed ROOFDECK TLS certificate metadata
Persistence ~/Library/LaunchAgents/*.plist Label starts with com., ProgramArguments includes --type=renderer, and RunAtLoad=true
Configuration file $HOME/.config/.repl_history ROOFDECK configuration file
HTTPS endpoint /app_version ROOFDECK tasking endpoint, with host resolved at runtime
Domain 185-66-91-112.cprapid[.]com Domain associated with the ub certificate user
Domain 213-111-146-132.cprapid[.]com Domain associated with the ub certificate user
Domain anesthesiaschool[.]com Domain associated with the ub certificate user
Domain app.heyhay[.]online Domain associated with the ub certificate user
Domain dela.servehttp[.]com Domain associated with the ub certificate user
Domain galaxy-royal[.]online Domain associated with the ub certificate user
Domain game.galaxy-royal[.]online Domain associated with the ub certificate user
Domain heyhay[.]online Domain associated with the ub certificate user
Domain mactroubleshoots[.]pro Domain associated with the ub certificate user
Domain mx01.galaxy-royal[.]online Domain associated with the ub certificate user
Domain ns4.galaxy-royal[.]online Domain associated with the ub certificate user
Domain tinklify[.]com Domain associated with the ub certificate user
Domain update.heyhay[.]online Domain associated with the ub certificate user
Domain vaimage[.]com Domain associated with the ub certificate user
Domain wss.sytes[.]net Domain associated with the ub certificate user
Domain www.anesthesiaschool[.]com Domain associated with the ub certificate user
Domain www.freehealth[.]lat Domain associated with the ub certificate user
Domain www.heyhay[.]online Domain associated with the ub certificate user
Domain www.mactroubleshoots[.]pro Domain associated with the ub certificate user
Domain www.tinklify[.]com Domain associated with the ub certificate user
Malicious provider domain registry.hashicorp-aws[.]com Typosquatted Terraform provider domain used in weaponized repositories
Malicious provider domain registry.hashicorp-aws[.]io Typosquatted Terraform provider domain used in weaponized repositories
Malicious provider domain registry.hashicorp-terraform[.]io Typosquatted Terraform provider domain used in weaponized repositories
GitHub repository github[.]com/exubient0/terraform-candidate-repo Repository containing a weaponized Terraform lock file
GitHub repository github[.]com/radupopa369/gtn-candidate-repo Repository containing a weaponized Terraform lock file
GitHub repository github[.]com/chainstacker/Northwind-IAC Repository associated with the hashicorp-aws[.]io provider lure
GitHub repository github[.]com/RyanLRay/Technical-Assessments Repository README referencing the weaponized provider domain
GitHub repository github[.]com/Steed-LHV/assessment Repository README referencing the hashicorp-terraform[.]io provider domain

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical HEIF Image Vulnerability Exploited for Remote Code Execution

Next Post

Microsoft Confirms September 2026 Windows Updates Break File History Backups

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
North Korean Hackers Use Fake Terraform Jobs to Deploy macOS Backdoors
September 21, 2026
Critical HEIF Image Vulnerability Exploited for Remote Code Execution
September 21, 2026
Microsoft-Signed Driver Exploited to Disable Security Tools, Steal Credentials
September 21, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us