SENTINELONE says the suspected North Korean group TraderTraitor, also tracked as UNC4899, Jade Sleet and PUKCHONG, has used fake recruitment exercises to compromise a developer workstation at an IT services organisation outside the cryptocurrency sector. The attackers approached software engineers through social media and directed them to GitHub repositories posing as coding assessments for fictional start-ups called Northwind and Novacart.
Weaponised Terraform lockfiles redirected `terraform init` to rogue provider registries, causing malicious modules to be downloaded and executed. The provider installed two ARM64 macOS backdoors, FLATROOF and ROOFDECK, which remained dormant for 11 days and activated when the victim opened a particular automation project in the Cursor editor. The compromised workstation contained production cloud access keys.
According to SentinelOne, FLATROOF masqueraded as a system update, removed quarantine attributes from the second implant and used an embedded Python module to collect browser histories from Safari, Chrome, Brave and Firefox, terminal histories, process lists and the local login keychain. The stolen data was sent through a Telegram bot.
ROOFDECK used public Nostr relays to locate its command server, verified commands with an embedded RSA public key, and supported file operations, clipboard capture and additional downloads. After several weeks of intermittent beaconing, the operators abandoned the machine and moved the malware to the system trash. SentinelOne attributes the activity to TraderTraitor with high confidence, but the report describes the group as suspected state-sponsored actors.
It recommends checking Terraform lockfiles and provider sources, monitoring developer endpoints and shell activity, and investigating unexpected connections to Nostr relays or Telegram bots.