Threats Tagged 'devops targeting'
View all threats tagged with 'devops targeting'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'devops targeting'
Click on any threat for detailed analysis and mitigation recommendations
In 2026, the DPRK-linked Lazarus subgroup TraderTraitor conducted attacks targeting cryptocurrency entities and also compromised a smaller Indian IT services provider with no crypto ties. The attack used social engineering via fake job interview lures containing weaponized Terraform projects. Victims executing terraform init downloaded macOS backdoors FLATROOF and ROOFDECK from malicious GitHub repositories using typosquatted domains. These backdoors enabled reconnaissance, credential theft, and cloud environment escalation. After public disclosure of a major LayerZero attack, the threat actor updated and redeployed a stripped ROOFDECK version and removed earlier implants. Activity ceased by June 2026 after the smaller target was deemed low value. Join the discussion | AlienVault OTX General | 09/19/2026, 08:44:15 UTC Added: 09/21/2026, 08:46:37 UTC |
Showing 1 to 1 of 1 result