Skip to main content

Suspected TraderTraitor Group Uses Trojanized Terraform Provider to Deliver Cross-Platform Malware

0
Medium
Published: 10/08/2026 (10/08/2026, 20:12:51 UTC)
Source: AlienVault OTX General

Description

In July 2026, a sophisticated malware campaign attributed to the TraderTraitor group was uncovered, leveraging a trojanized Terraform provider to target cryptocurrency and Web3 developers. The attack uses a malicious Terraform provider that downloads a Bash loader from a HashiCorp-themed lookalike domain, which then deploys platform-specific payloads for macOS, Linux, and Windows. Encrypted executables are hidden in fake font files and decrypted with AES-256-CBC. The campaign delivers FLATROOF, a Rust-based backdoor with multiple command and control (C2) channels, and Python-based information stealers targeting browser credentials and cryptocurrency wallet data. The attack concludes with deployment of the ROOFDECK backdoor, which uses resilient C2 discovery methods including cryptographically signed Pastebin dead drops and Nostr metadata.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/09/2026, 09:05:52 UTC

Technical Analysis

This threat involves a multi-stage malware campaign by the TraderTraitor group using a trojanized Terraform provider as the initial infection vector. The malicious provider downloads a Bash loader from a domain mimicking HashiCorp's infrastructure, which selects and deploys payloads tailored to the victim's OS (macOS, Linux, Windows). Encrypted payloads are concealed within fake font files and decrypted using AES-256-CBC. The campaign installs FLATROOF, a Rust-based backdoor with platform-specific persistence and multiple C2 channels such as Telegram Bot API and GitHub. Additionally, Python-based stealers exfiltrate browser credentials, cookies, cryptocurrency wallet extensions, and system information. The final stage deploys the ROOFDECK backdoor, which uses cryptographically signed Pastebin dead drops and Nostr profile metadata for resilient C2 communication. Indicators include multiple malicious domains and file hashes. No CVE or patch information is available.

Potential Impact

The campaign targets cryptocurrency and Web3 developers, potentially compromising sensitive credentials, cookies, wallet extensions, and system information across multiple operating systems. The malware provides persistent backdoors with multiple C2 channels, enabling ongoing unauthorized access and data exfiltration. The use of trojanized infrastructure-as-code providers increases the risk of supply chain compromise in development environments.

Defensive Guidance

No official patch or remediation is indicated. Defenders should avoid using untrusted or unofficial Terraform providers and verify the authenticity of providers and domains before use. Monitoring for indicators of compromise such as the listed malicious domains and hashes is recommended. Since this is a malware campaign rather than a software vulnerability, remediation involves detection and removal of the malware and securing development environments against supply chain attacks.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.zscaler.com/blogs/security-research/suspected-tradertraitor-group-uses-trojanized-terraform-provider-deliver"]
Adversary
TraderTraitor
Pulse Id
6ac7f9431e9712b6c5e2a6cd

Indicators of Compromise

Domain

ValueDescriptionCopy
domaindelay.servehttp.com
—
domaindiagnose.hashicorp-terraform.io
—
domainarusupport-region1-webhook.online
—
domainhashicorp-terraform.io
—
domainsupportaru.serveftp.com
—

Hash

ValueDescriptionCopy
hash188bd4fc222c9615540884920caf37ea88bcbea7488e1fb98709e357dd096666
—
hash451b586ec9d3c997b319986a1177829653e8ae641c953c05ede6a38616f2da97
—
hash9d78ece09457907b730d139e4e0c64dd
—
hash8473f85bda00dfa3ecd2385dd38f69600d1d64a6
—
hash116f7189ed7b41f1b339a749d56e63be
—
hash2621753691be9521288664bb551dfba6
—
hash2b81aceab0142472d94eb42e500b27b1
—
hash34a52e6a4d803e94fe497bab682abfd3
—
hash3826dc7a9ba8bd5b1c143560c1530d89
—
hash4b8509cde757b5428e5f99c8dffe73ca
—
hash58fa0d651898446d5f5d2ed8a27a3330
—
hash73adaea97f003735335505858c1c6def
—
hash9d88b4494c7bc27b10358b68a899ad54
—
hashad0b1b6d2c8b9d09d6473a4a299470ab
—
hashbe60c52ca8a01fef7dc15c2f0ebb77d8
—
hashd81081691c3631f3adc1a6db0ee22ab19682ef30
—

Url

ValueDescriptionCopy
urlhttps://arusupport-region1-webhook.online/statics/cache/v11/abicfjej
—
urlhttps://diagnose.hashicorp-terraform.io/plugins/grpc/v6/schema/metrics/333afe63-c5a2-43f0-b046-7cbaa7797e8a
—
urlhttps://supportaru.serveftp.com/statics/cache/v11/
—

Threat ID: 6ac8aa722cdf04f65640584f

Added to database: 10/09/2026, 08:48:50 UTC

Last enriched: 10/09/2026, 09:05:52 UTC

Last updated: 10/09/2026, 18:48:09 UTC

Views: 21

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses