Threats Tagged 'tradertraitor'
View all threats tagged with 'tradertraitor'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'tradertraitor'
Click on any threat for detailed analysis and mitigation recommendations
In July 2026, a sophisticated malware campaign attributed to the TraderTraitor group was uncovered, leveraging a trojanized Terraform provider to target cryptocurrency and Web3 developers. The attack uses a malicious Terraform provider that downloads a Bash loader from a HashiCorp-themed lookalike domain, which then deploys platform-specific payloads for macOS, Linux, and Windows. Encrypted executables are hidden in fake font files and decrypted with AES-256-CBC. The campaign delivers FLATROOF, a Rust-based backdoor with multiple command and control (C2) channels, and Python-based information stealers targeting browser credentials and cryptocurrency wallet data. The attack concludes with deployment of the ROOFDECK backdoor, which uses resilient C2 discovery methods including cryptographically signed Pastebin dead drops and Nostr metadata. Join the discussion | AlienVault OTX General | 10/08/2026, 20:12:51 UTC Added: 10/09/2026, 08:48:50 UTC |
Showing 1 to 1 of 1 result