A marketing campaign in July 2026 utilizing a trojanized Terraform supplier to deploy cross-platform malware in opposition to developer environments.
The operation delivers FLATROOF for credential theft and preliminary entry, adopted by ROOFDECK for broader distant management.
Attribution stays provisional. ThreatLabz discovered similarities in concentrating on, tooling, and techniques however lacked distinctive code matches, shared infrastructure, or cryptographic proof adequate for unbiased, high-confidence attribution.
The preliminary supply mechanism for the analyzed supplier additionally stays unresolved.
The Go binary, terraform-provider-awsbeta_v1.0.0, impersonates an AWS Terraform supplier whereas retaining a practical supplier scaffold.
Attackers inserted a malicious awsbeta bundle and invoked it immediately from essential, triggering execution when Terraform begins the plugin.
The implant checks for session.lock within the short-term listing earlier than downloading a Bash loader from hashicorp-terraform[.]io.
It saves the script as safari_updater, grants execution permissions, launches a indifferent course of, and creates the marker to suppress repeat execution. Regular supplier conduct continues, decreasing seen disruption.
The loader identifies the working system and processor structure, then selects an encrypted payload disguised as a .woff font.

Zscaler ThreatLabz mentioned in a report shared with GBhackers, important overlap with TraderTraitor, a North Korean state-backed actor tracked as Jade Sleet, UNC4899, Strain Chollima, and Sluggish Pisces.
Terraform Provide Chain
Linux, macOS, and Home windows use NotoSansCJK, HiraginoSans, and MalgunGothic filenames respectively; Home windows execution requires a suitable Unix-like shell surroundings.
The primary is a 64-bit Home windows executable that’s decoded utilizing the XOR key 0x37 and injected right into a suspended Chromium course of to get better grasp encryption keys.
Downloads fall again throughout dynamic DNS infrastructure, GitHub, and Vercel. Every file combines decoy font content material with an @@ENDFONT@@ marker and encrypted executable.

The loader extracts the appended content material, Base64-decodes it, and applies AES-256-CBC decryption by means of out there Python, Node.js, Perl, or OpenSSL tooling.
On macOS, it removes the quarantine attribute and applies an advert hoc signature earlier than execution.
The Rust-based FLATROOF backdoor decrypts its configuration utilizing PBKDF2-HMAC-SHA256 and AES-256-GCM.
Its code helps Telegram, GitHub API polling, and attacker-controlled HTTP webhooks, though particular person samples don’t essentially configure each channel.
Persistence varies by platform: Linux providers, macOS shell logout mechanisms, and Home windows registry Run values.
Embedded Python collectors harvest browser databases, cookies, saved credential artifacts, terminal histories, utility inventories, and host data.
Platform-specific assortment contains Linux keyrings, macOS login.keychain-db, and Home windows Credential Supervisor entries. Home windows scripts moreover goal MetaMask, Phantom, Belief Pockets, and Rabby extension information.
An embedded native element executes inside a suspended Chromium course of to get better browser encryption keys.

ROOFDECK resolves its command-and-control deal with by means of native configuration, a signed and encrypted Pastebin lifeless drop, or Nostr profile metadata.
RSA signature verification prevents unauthorized alternative of the accepted server deal with. Nostr’s profile web site area can redirect the implant to the present Pastebin location.
As soon as related over HTTP or WebSocket endpoints, ROOFDECK helps reconnaissance, interactive shells, file transfers, clipboard entry, persistence administration, and self-removal.
The malware overlaps with the KelpDAO incident report, which documented developer compromise previous the $292 million bridge theft.
SentinelLabs’ associated investigation additionally recognized an Indian IT-services sufferer with out cryptocurrency ties. Earlier Unit 42 analysis documented recruiter impersonation and malicious coding challenges concentrating on builders.
Organizations ought to prohibit untrusted suppliers, confirm checksums in opposition to trusted sources, examine equipped lockfiles, and monitor sudden provider-spawned processes.
SentinelLabs recommends scrutinizing unfamiliar registries and separating exterior interview assignments from company workstations, notably the place engineers maintain cloud credentials or source-control entry.
Indicators Of Compromise
| Indicator | File title | Description |
|---|---|---|
| 9d78ece09457907b730d139e4e0c64dd | terraform-provider-awsbeta_v1.0.0 | Trojanized Terraform supplier |
| 73adaea97f003735335505858c1c6def | safari_updater | Bash script |
| 116f7189ed7b41f1b339a749d56e63be | HiraginoSans-Daring.woff | Encrypted Mach-O 64-bit x86_64 FLATROOF |
| be60c52ca8a01fef7dc15c2f0ebb77d8 | HiraginoSans-Common.woff | Encrypted Mach-O 64-bit arm64 FLATROOF |
| 58fa0d651898446d5f5d2ed8a27a3330 | MalgunGothic-Daring.woff | Encrypted PE32+ FLATROOF |
Word: IP addresses and domains are deliberately defanged (e.g., [.]) to stop unintentional decision or hyperlinking. Re-fang solely inside managed menace intelligence platforms akin to MISP, VirusTotal, or your SIEM.
Stops Cyber threats earlier than affect with 21 min quicker MTTR. Combine ANYRUN’s Sandbox in your SOC.







![11 social media tendencies each marketer ought to watch in 2026 [new data]](https://blog.aimactgrow.com/wp-content/uploads/2026/09/social20media20trends-1-120x86.png)

