Skip to main content

Don't Call Us, We'll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties

0
Medium
Published: 09/19/2026 (09/19/2026, 08:44:15 UTC)
Source: AlienVault OTX General

Description

In 2026, the DPRK-linked Lazarus subgroup TraderTraitor conducted attacks targeting cryptocurrency entities and also compromised a smaller Indian IT services provider with no crypto ties. The attack used social engineering via fake job interview lures containing weaponized Terraform projects. Victims executing terraform init downloaded macOS backdoors FLATROOF and ROOFDECK from malicious GitHub repositories using typosquatted domains. These backdoors enabled reconnaissance, credential theft, and cloud environment escalation. After public disclosure of a major LayerZero attack, the threat actor updated and redeployed a stripped ROOFDECK version and removed earlier implants. Activity ceased by June 2026 after the smaller target was deemed low value.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/21/2026, 09:01:53 UTC

Technical Analysis

The Lazarus subgroup TraderTraitor targeted cryptocurrency organizations and a non-crypto Indian IT services provider in 2026 using social engineering involving fake job interview Terraform projects. Malicious GitHub repositories with typosquatted provider domains delivered macOS backdoors FLATROOF and ROOFDECK during terraform init execution. These backdoors facilitated reconnaissance, credential theft, and escalation within cloud environments. Following a $292 million theft from KelpDAO via LayerZero, the attackers updated ROOFDECK implants and removed prior backdoors on the secondary victim. The intrusion activity continued until June 2026 before abandonment due to insufficient value from the smaller target.

Potential Impact

The threat actor achieved initial compromise through social engineering and supply chain abuse of Terraform projects, leading to deployment of macOS backdoors. These backdoors enabled reconnaissance, credential theft, and escalation of privileges in cloud environments. The attacks resulted in significant financial theft in the cryptocurrency sector and potential exposure of sensitive credentials and cloud resources in the non-crypto IT services victim. The secondary victim was ultimately abandoned after assessment of low value.

Defensive Guidance

No official patch or remediation guidance is provided. Organizations should be aware of social engineering attacks leveraging fake job interview lures and weaponized Terraform projects. Avoid executing untrusted Terraform code, especially from unknown or typosquatted GitHub repositories. Monitor for suspicious terraform init activity and macOS backdoor indicators. Since this is not a software vulnerability with a patch, mitigation focuses on operational security and supply chain vigilance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.sentinelone.com/labs/dont-call-us-well-call-your-apis-tradertraitor-backdoors-resurface-on-victim-with-no-crypto-ties/"]
Adversary
TraderTraitor
Pulse Id
6aae4b5f7a0d5f15edf2a5f1

Indicators of Compromise

Domain

ValueDescriptionCopy
domaintechnicais.sytes.net
domaintechnicais.sytes.net
domainstorage.hubpage.cloud
domainstorage.hubpage.cloud
domaingrenight.com
domaingrenight.com

Hash

ValueDescriptionCopy
hash77b4fd46994992f0e57302cfe76ed23c0d90101381d2b89fc2ddf5c4536e77ca
SHA256 of c491d477dbe0ae04e9aed9dbe237144c03f73ec4
hash77b4fd46994992f0e57302cfe76ed23c0d90101381d2b89fc2ddf5c4536e77ca
hash77b4fd46994992f0e57302cfe76ed23c0d90101381d2b89fc2ddf5c4536e77ca
SHA256 of c491d477dbe0ae04e9aed9dbe237144c03f73ec4
hashd95dede4387ff516f4c23351c450427d
MD5 of c491d477dbe0ae04e9aed9dbe237144c03f73ec4
hashd95dede4387ff516f4c23351c450427d
hashd95dede4387ff516f4c23351c450427d
MD5 of c491d477dbe0ae04e9aed9dbe237144c03f73ec4
hashc491d477dbe0ae04e9aed9dbe237144c03f73ec4
hashc491d477dbe0ae04e9aed9dbe237144c03f73ec4
hashc491d477dbe0ae04e9aed9dbe237144c03f73ec4
hash02df07a173ab03b82a4fb6a08973fff8b1467f28
hash02df07a173ab03b82a4fb6a08973fff8b1467f28
hash02df07a173ab03b82a4fb6a08973fff8b1467f28
hash5728b11d30586bbfc1d8bd12df1c722a06e767a2
hash5728b11d30586bbfc1d8bd12df1c722a06e767a2
hash5728b11d30586bbfc1d8bd12df1c722a06e767a2
hash4b2d3e8ccce8920a6d01e7d02b84236545a20e5f754b3eec253f8b416b731daa
hash4ad92bf92ee614b05c340ce17bef7b6ef5a25e82
hash1cd6d13ff15adbf7a42025d10ec99b4a
hashc43f594fac7544e5485cbbe441e470bf
MD5 of 5728b11d30586bbfc1d8bd12df1c722a06e767a2
hashc43f594fac7544e5485cbbe441e470bf
MD5 of 5728b11d30586bbfc1d8bd12df1c722a06e767a2
hashc43f594fac7544e5485cbbe441e470bf
hash19af09ebe8b7ad03419677dda515507dd099bc39
hash930e5be6d34511bedbfb0d762bd08fffe64e9630
hashf3404ef308098202246f2f3c38c8c3166e9a8e7843ec69c1b11ac0ce9cb4038e
SHA256 of 5728b11d30586bbfc1d8bd12df1c722a06e767a2
hashf3404ef308098202246f2f3c38c8c3166e9a8e7843ec69c1b11ac0ce9cb4038e
hashf3404ef308098202246f2f3c38c8c3166e9a8e7843ec69c1b11ac0ce9cb4038e
SHA256 of 5728b11d30586bbfc1d8bd12df1c722a06e767a2

Ip

ValueDescriptionCopy
ip45.11.59.140
CC=UA ASN=AS30860 virtual systems llc
ip45.11.59.140
ip45.11.59.140
CC=UA ASN=AS30860 virtual systems llc
ip176.97.114.232
CC=UA ASN=ASNone
ip176.97.114.232
CC=UA ASN=ASNone
ip85.137.56.245
CC=ES ASN=AS6739 vodafone ono s.a.
ip85.137.56.245
CC=ES ASN=AS6739 vodafone ono s.a.
ip85.137.56.10
CC=ES ASN=AS6739 vodafone ono s.a.
ip85.137.56.10
ip85.137.56.10
CC=ES ASN=AS6739 vodafone ono s.a.

Threat ID: 6ab0eeed55bf5e2cf599878d

Added to database: 09/21/2026, 08:46:37 UTC

Last enriched: 09/21/2026, 09:01:53 UTC

Last updated: 09/21/2026, 18:45:30 UTC

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses