Don't Call Us, We'll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties
In 2026, the DPRK-linked Lazarus subgroup TraderTraitor conducted attacks targeting cryptocurrency entities and also compromised a smaller Indian IT services provider with no crypto ties. The attack used social engineering via fake job interview lures containing weaponized Terraform projects. Victims executing terraform init downloaded macOS backdoors FLATROOF and ROOFDECK from malicious GitHub repositories using typosquatted domains. These backdoors enabled reconnaissance, credential theft, and cloud environment escalation. After public disclosure of a major LayerZero attack, the threat actor updated and redeployed a stripped ROOFDECK version and removed earlier implants. Activity ceased by June 2026 after the smaller target was deemed low value.
AI Analysis
Technical Summary
The Lazarus subgroup TraderTraitor targeted cryptocurrency organizations and a non-crypto Indian IT services provider in 2026 using social engineering involving fake job interview Terraform projects. Malicious GitHub repositories with typosquatted provider domains delivered macOS backdoors FLATROOF and ROOFDECK during terraform init execution. These backdoors facilitated reconnaissance, credential theft, and escalation within cloud environments. Following a $292 million theft from KelpDAO via LayerZero, the attackers updated ROOFDECK implants and removed prior backdoors on the secondary victim. The intrusion activity continued until June 2026 before abandonment due to insufficient value from the smaller target.
Potential Impact
The threat actor achieved initial compromise through social engineering and supply chain abuse of Terraform projects, leading to deployment of macOS backdoors. These backdoors enabled reconnaissance, credential theft, and escalation of privileges in cloud environments. The attacks resulted in significant financial theft in the cryptocurrency sector and potential exposure of sensitive credentials and cloud resources in the non-crypto IT services victim. The secondary victim was ultimately abandoned after assessment of low value.
Mitigation Recommendations
No official patch or remediation guidance is provided. Organizations should be aware of social engineering attacks leveraging fake job interview lures and weaponized Terraform projects. Avoid executing untrusted Terraform code, especially from unknown or typosquatted GitHub repositories. Monitor for suspicious terraform init activity and macOS backdoor indicators. Since this is not a software vulnerability with a patch, mitigation focuses on operational security and supply chain vigilance.
Indicators of Compromise
- domain: technicais.sytes.net
- domain: technicais.sytes.net
- domain: storage.hubpage.cloud
- domain: storage.hubpage.cloud
- hash: 77b4fd46994992f0e57302cfe76ed23c0d90101381d2b89fc2ddf5c4536e77ca
- hash: 77b4fd46994992f0e57302cfe76ed23c0d90101381d2b89fc2ddf5c4536e77ca
- hash: 77b4fd46994992f0e57302cfe76ed23c0d90101381d2b89fc2ddf5c4536e77ca
- hash: d95dede4387ff516f4c23351c450427d
- hash: d95dede4387ff516f4c23351c450427d
- hash: d95dede4387ff516f4c23351c450427d
- hash: c491d477dbe0ae04e9aed9dbe237144c03f73ec4
- hash: c491d477dbe0ae04e9aed9dbe237144c03f73ec4
- hash: c491d477dbe0ae04e9aed9dbe237144c03f73ec4
- ip: 45.11.59.140
- ip: 45.11.59.140
- ip: 45.11.59.140
- domain: grenight.com
- domain: grenight.com
- ip: 176.97.114.232
- ip: 176.97.114.232
- ip: 85.137.56.245
- ip: 85.137.56.245
- ip: 85.137.56.10
- ip: 85.137.56.10
- ip: 85.137.56.10
- hash: 02df07a173ab03b82a4fb6a08973fff8b1467f28
- hash: 02df07a173ab03b82a4fb6a08973fff8b1467f28
- hash: 02df07a173ab03b82a4fb6a08973fff8b1467f28
- hash: 5728b11d30586bbfc1d8bd12df1c722a06e767a2
- hash: 5728b11d30586bbfc1d8bd12df1c722a06e767a2
- hash: 5728b11d30586bbfc1d8bd12df1c722a06e767a2
- hash: 4b2d3e8ccce8920a6d01e7d02b84236545a20e5f754b3eec253f8b416b731daa
- hash: 4ad92bf92ee614b05c340ce17bef7b6ef5a25e82
- hash: 1cd6d13ff15adbf7a42025d10ec99b4a
- hash: c43f594fac7544e5485cbbe441e470bf
- hash: c43f594fac7544e5485cbbe441e470bf
- hash: c43f594fac7544e5485cbbe441e470bf
- hash: 19af09ebe8b7ad03419677dda515507dd099bc39
- hash: 930e5be6d34511bedbfb0d762bd08fffe64e9630
- hash: f3404ef308098202246f2f3c38c8c3166e9a8e7843ec69c1b11ac0ce9cb4038e
- hash: f3404ef308098202246f2f3c38c8c3166e9a8e7843ec69c1b11ac0ce9cb4038e
- hash: f3404ef308098202246f2f3c38c8c3166e9a8e7843ec69c1b11ac0ce9cb4038e
Don't Call Us, We'll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties
Description
In 2026, the DPRK-linked Lazarus subgroup TraderTraitor conducted attacks targeting cryptocurrency entities and also compromised a smaller Indian IT services provider with no crypto ties. The attack used social engineering via fake job interview lures containing weaponized Terraform projects. Victims executing terraform init downloaded macOS backdoors FLATROOF and ROOFDECK from malicious GitHub repositories using typosquatted domains. These backdoors enabled reconnaissance, credential theft, and cloud environment escalation. After public disclosure of a major LayerZero attack, the threat actor updated and redeployed a stripped ROOFDECK version and removed earlier implants. Activity ceased by June 2026 after the smaller target was deemed low value.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Lazarus subgroup TraderTraitor targeted cryptocurrency organizations and a non-crypto Indian IT services provider in 2026 using social engineering involving fake job interview Terraform projects. Malicious GitHub repositories with typosquatted provider domains delivered macOS backdoors FLATROOF and ROOFDECK during terraform init execution. These backdoors facilitated reconnaissance, credential theft, and escalation within cloud environments. Following a $292 million theft from KelpDAO via LayerZero, the attackers updated ROOFDECK implants and removed prior backdoors on the secondary victim. The intrusion activity continued until June 2026 before abandonment due to insufficient value from the smaller target.
Potential Impact
The threat actor achieved initial compromise through social engineering and supply chain abuse of Terraform projects, leading to deployment of macOS backdoors. These backdoors enabled reconnaissance, credential theft, and escalation of privileges in cloud environments. The attacks resulted in significant financial theft in the cryptocurrency sector and potential exposure of sensitive credentials and cloud resources in the non-crypto IT services victim. The secondary victim was ultimately abandoned after assessment of low value.
Defensive Guidance
No official patch or remediation guidance is provided. Organizations should be aware of social engineering attacks leveraging fake job interview lures and weaponized Terraform projects. Avoid executing untrusted Terraform code, especially from unknown or typosquatted GitHub repositories. Monitor for suspicious terraform init activity and macOS backdoor indicators. Since this is not a software vulnerability with a patch, mitigation focuses on operational security and supply chain vigilance.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.sentinelone.com/labs/dont-call-us-well-call-your-apis-tradertraitor-backdoors-resurface-on-victim-with-no-crypto-ties/"]
- Adversary
- TraderTraitor
- Pulse Id
- 6aae4b5f7a0d5f15edf2a5f1
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaintechnicais.sytes.net | — | |
domaintechnicais.sytes.net | — | |
domainstorage.hubpage.cloud | — | |
domainstorage.hubpage.cloud | — | |
domaingrenight.com | — | |
domaingrenight.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash77b4fd46994992f0e57302cfe76ed23c0d90101381d2b89fc2ddf5c4536e77ca | SHA256 of c491d477dbe0ae04e9aed9dbe237144c03f73ec4 | |
hash77b4fd46994992f0e57302cfe76ed23c0d90101381d2b89fc2ddf5c4536e77ca | — | |
hash77b4fd46994992f0e57302cfe76ed23c0d90101381d2b89fc2ddf5c4536e77ca | SHA256 of c491d477dbe0ae04e9aed9dbe237144c03f73ec4 | |
hashd95dede4387ff516f4c23351c450427d | MD5 of c491d477dbe0ae04e9aed9dbe237144c03f73ec4 | |
hashd95dede4387ff516f4c23351c450427d | — | |
hashd95dede4387ff516f4c23351c450427d | MD5 of c491d477dbe0ae04e9aed9dbe237144c03f73ec4 | |
hashc491d477dbe0ae04e9aed9dbe237144c03f73ec4 | — | |
hashc491d477dbe0ae04e9aed9dbe237144c03f73ec4 | — | |
hashc491d477dbe0ae04e9aed9dbe237144c03f73ec4 | — | |
hash02df07a173ab03b82a4fb6a08973fff8b1467f28 | — | |
hash02df07a173ab03b82a4fb6a08973fff8b1467f28 | — | |
hash02df07a173ab03b82a4fb6a08973fff8b1467f28 | — | |
hash5728b11d30586bbfc1d8bd12df1c722a06e767a2 | — | |
hash5728b11d30586bbfc1d8bd12df1c722a06e767a2 | — | |
hash5728b11d30586bbfc1d8bd12df1c722a06e767a2 | — | |
hash4b2d3e8ccce8920a6d01e7d02b84236545a20e5f754b3eec253f8b416b731daa | — | |
hash4ad92bf92ee614b05c340ce17bef7b6ef5a25e82 | — | |
hash1cd6d13ff15adbf7a42025d10ec99b4a | — | |
hashc43f594fac7544e5485cbbe441e470bf | MD5 of 5728b11d30586bbfc1d8bd12df1c722a06e767a2 | |
hashc43f594fac7544e5485cbbe441e470bf | MD5 of 5728b11d30586bbfc1d8bd12df1c722a06e767a2 | |
hashc43f594fac7544e5485cbbe441e470bf | — | |
hash19af09ebe8b7ad03419677dda515507dd099bc39 | — | |
hash930e5be6d34511bedbfb0d762bd08fffe64e9630 | — | |
hashf3404ef308098202246f2f3c38c8c3166e9a8e7843ec69c1b11ac0ce9cb4038e | SHA256 of 5728b11d30586bbfc1d8bd12df1c722a06e767a2 | |
hashf3404ef308098202246f2f3c38c8c3166e9a8e7843ec69c1b11ac0ce9cb4038e | — | |
hashf3404ef308098202246f2f3c38c8c3166e9a8e7843ec69c1b11ac0ce9cb4038e | SHA256 of 5728b11d30586bbfc1d8bd12df1c722a06e767a2 |
Ip
| Value | Description | Copy |
|---|---|---|
ip45.11.59.140 | CC=UA ASN=AS30860 virtual systems llc | |
ip45.11.59.140 | — | |
ip45.11.59.140 | CC=UA ASN=AS30860 virtual systems llc | |
ip176.97.114.232 | CC=UA ASN=ASNone | |
ip176.97.114.232 | CC=UA ASN=ASNone | |
ip85.137.56.245 | CC=ES ASN=AS6739 vodafone ono s.a. | |
ip85.137.56.245 | CC=ES ASN=AS6739 vodafone ono s.a. | |
ip85.137.56.10 | CC=ES ASN=AS6739 vodafone ono s.a. | |
ip85.137.56.10 | — | |
ip85.137.56.10 | CC=ES ASN=AS6739 vodafone ono s.a. |
Threat ID: 6ab0eeed55bf5e2cf599878d
Added to database: 09/21/2026, 08:46:37 UTC
Last enriched: 09/21/2026, 09:01:53 UTC
Last updated: 09/21/2026, 18:45:30 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.