Suspected TraderTraitor Group Uses Trojanized Terraform Provider to Deliver Cross-Platform Malware
Description
In July 2026, a sophisticated malware campaign attributed to the TraderTraitor group was uncovered, leveraging a trojanized Terraform provider to target cryptocurrency and Web3 developers. The attack uses a malicious Terraform provider that downloads a Bash loader from a HashiCorp-themed lookalike domain, which then deploys platform-specific payloads for macOS, Linux, and Windows. Encrypted executables are hidden in fake font files and decrypted with AES-256-CBC. The campaign delivers FLATROOF, a Rust-based backdoor with multiple command and control (C2) channels, and Python-based information stealers targeting browser credentials and cryptocurrency wallet data. The attack concludes with deployment of the ROOFDECK backdoor, which uses resilient C2 discovery methods including cryptographically signed Pastebin dead drops and Nostr metadata.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves a multi-stage malware campaign by the TraderTraitor group using a trojanized Terraform provider as the initial infection vector. The malicious provider downloads a Bash loader from a domain mimicking HashiCorp's infrastructure, which selects and deploys payloads tailored to the victim's OS (macOS, Linux, Windows). Encrypted payloads are concealed within fake font files and decrypted using AES-256-CBC. The campaign installs FLATROOF, a Rust-based backdoor with platform-specific persistence and multiple C2 channels such as Telegram Bot API and GitHub. Additionally, Python-based stealers exfiltrate browser credentials, cookies, cryptocurrency wallet extensions, and system information. The final stage deploys the ROOFDECK backdoor, which uses cryptographically signed Pastebin dead drops and Nostr profile metadata for resilient C2 communication. Indicators include multiple malicious domains and file hashes. No CVE or patch information is available.
Potential Impact
The campaign targets cryptocurrency and Web3 developers, potentially compromising sensitive credentials, cookies, wallet extensions, and system information across multiple operating systems. The malware provides persistent backdoors with multiple C2 channels, enabling ongoing unauthorized access and data exfiltration. The use of trojanized infrastructure-as-code providers increases the risk of supply chain compromise in development environments.
Defensive Guidance
No official patch or remediation is indicated. Defenders should avoid using untrusted or unofficial Terraform providers and verify the authenticity of providers and domains before use. Monitoring for indicators of compromise such as the listed malicious domains and hashes is recommended. Since this is a malware campaign rather than a software vulnerability, remediation involves detection and removal of the malware and securing development environments against supply chain attacks.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.zscaler.com/blogs/security-research/suspected-tradertraitor-group-uses-trojanized-terraform-provider-deliver"]
- Adversary
- TraderTraitor
- Pulse Id
- 6ac7f9431e9712b6c5e2a6cd
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaindelay.servehttp.com | — | |
domaindiagnose.hashicorp-terraform.io | — | |
domainarusupport-region1-webhook.online | — | |
domainhashicorp-terraform.io | — | |
domainsupportaru.serveftp.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash188bd4fc222c9615540884920caf37ea88bcbea7488e1fb98709e357dd096666 | — | |
hash451b586ec9d3c997b319986a1177829653e8ae641c953c05ede6a38616f2da97 | — | |
hash9d78ece09457907b730d139e4e0c64dd | — | |
hash8473f85bda00dfa3ecd2385dd38f69600d1d64a6 | — | |
hash116f7189ed7b41f1b339a749d56e63be | — | |
hash2621753691be9521288664bb551dfba6 | — | |
hash2b81aceab0142472d94eb42e500b27b1 | — | |
hash34a52e6a4d803e94fe497bab682abfd3 | — | |
hash3826dc7a9ba8bd5b1c143560c1530d89 | — | |
hash4b8509cde757b5428e5f99c8dffe73ca | — | |
hash58fa0d651898446d5f5d2ed8a27a3330 | — | |
hash73adaea97f003735335505858c1c6def | — | |
hash9d88b4494c7bc27b10358b68a899ad54 | — | |
hashad0b1b6d2c8b9d09d6473a4a299470ab | — | |
hashbe60c52ca8a01fef7dc15c2f0ebb77d8 | — | |
hashd81081691c3631f3adc1a6db0ee22ab19682ef30 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://arusupport-region1-webhook.online/statics/cache/v11/abicfjej | — | |
urlhttps://diagnose.hashicorp-terraform.io/plugins/grpc/v6/schema/metrics/333afe63-c5a2-43f0-b046-7cbaa7797e8a | — | |
urlhttps://supportaru.serveftp.com/statics/cache/v11/ | — |
Threat ID: 6ac8aa722cdf04f65640584f
Added to database: 10/09/2026, 08:48:50 UTC
Last enriched: 10/09/2026, 09:05:52 UTC
Last updated: 10/09/2026, 18:48:09 UTC
Views: 21
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.