SOC Prime Bias: Critical

09 Oct 2026 13:11 UTC

TraderTraitor-Linked Attack Abuses Terraform Provider to Spread Cross-Platform Malware

Author Photo
SOC Prime Team linkedin icon Follow
TraderTraitor-Linked Attack Abuses Terraform Provider to Spread Cross-Platform Malware
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

The TraderTraitor group is conducting a campaign that uses a trojanized Terraform provider to distribute cross-platform malware. The infection chain relies on a Bash loader that selects payloads for macOS, Linux, and Windows before deploying FLATROOF and ROOFDECK malware. These tools focus on data theft, targeting cryptocurrency credentials and browser information while maintaining resilient command-and-control communications.

Investigation

Zscaler ThreatLabz uncovered a malicious Go-based Terraform provider named terraform-provider-awsbeta_v1.0.0 that executes embedded code when loaded. Researchers identified a multi-stage delivery chain involving .woff files disguised as fonts and layered C2 discovery through Pastebin and Nostr metadata. Analysis also confirmed capabilities to bypass macOS Gatekeeper and perform process injection on Windows systems.

Mitigation

Organizations should restrict the use of untrusted Terraform providers and enforce strict validation of provider checksums. Monitoring for unexpected child processes launched by developer tools and CI/CD systems is recommended. Security teams should also restrict outbound connections to unverified domains and monitor unusual file activity within temporary directories to reduce exposure.

Response

When malicious activity is detected, immediately isolate affected developer workstations and CI/CD environments to prevent additional compromise or lateral movement. Conduct a comprehensive forensic investigation to determine the scope of data exfiltration, focusing on browser credentials and cryptocurrency wallets. Rotate all secrets, API keys, and credentials that may have been accessible from compromised systems.

Attack Flow

Detections

Possible Telegram Abuse As Command And Control Channel (via dns_query)

SOC Prime Team
09 Oct 2026

Possible Data Infiltration / Exfiltration / C2 via Third Party Services / Tools (via proxy)

SOC Prime Team
09 Oct 2026

Suspicious Pastebin Domain Communications Attempt (via proxy)

SOC Prime Team
09 Oct 2026

Probable Encryption Or Decryption of Files with OpenSSL [MacOS] (via cmdline)

SOC Prime Team
09 Oct 2026

Possible Base64 Encoded Strings Manipulation [MacOS] (via cmdline)

SOC Prime Team
09 Oct 2026

MacOS Suspicious Tmp Folder File Permissions Modification (via cmdline)

SOC Prime Team
09 Oct 2026

MacOS Suspicious File Was Copied (via cmdline)

SOC Prime Team
09 Oct 2026

Possible Multi-File Staging in TMP Directory for Exfiltration (via file_event)

SOC Prime Team
09 Oct 2026

Archive Was Created In MacOS Temporary Folder (via file_event)

SOC Prime Team
09 Oct 2026

Suspicious Chmod Execution Pointing To Suspicious Directories (via cmdline)

SOC Prime Team
09 Oct 2026

IOCs (HashMd5) to detect: Suspected TraderTraitor Group Uses Trojanized Terraform Provider to Deliver Cross-Platform Malware

SOC Prime AI Rules
09 Oct 2026

ROOFDECK and FLATROOF Command and Control Detection [Windows Network Connection]

SOC Prime AI Rules
09 Oct 2026

MacOS Quarantine Attribute Removal via xattr [Windows Sysmon]

SOC Prime AI Rules
09 Oct 2026

Detection of Safari Updater Bash Script Execution [Linux Process Creation]

SOC Prime AI Rules
09 Oct 2026

Detection of Malicious Safari Updater and Encrypted Payload [Windows Process Creation]

SOC Prime AI Rules
09 Oct 2026

Simulation Execution

  • Attack Narrative & Commands: An attacker has successfully downloaded a malicious payload (e.g., payload.dmg) via a web browser. Due to macOS Gatekeeper, the file is flagged with the com.apple.quarantine attribute. To prevent the user from seeing a “This app was downloaded from the internet” warning and to bypass signature verification checks upon execution, the attacker executes a shell command to strip this attribute. The attacker’s goal is to execute the payload silently to establish a Command and Control (C2) channel.

  • Regression Test Script:

    #!/bin/bash
    # Simulation: Remove quarantine attribute to bypass Gatekeeper
    
    # 1. Create a dummy file to act as the "malicious" payload
    TARGET_FILE="/tmp/malicious_payload.txt"
    touch "$TARGET_FILE"
    
    # 2. Simulate the quarantine attribute being present (manually applying it)
    # Note: In a real scenario, this happens automatically via browser downloads
    xattr -w com.apple.quarantine "0081;65a12345;Chrome;" "$TARGET_FILE"
    echo "[+] Simulated quarantine attribute applied to $TARGET_FILE"
    
    # 3. Execute the specific command the detection rule is looking for
    echo "[!] Executing attack command..."
    /usr/bin/xattr -d com.apple.quarantine "$TARGET_FILE"
    
    # 4. Verify if the attribute is gone
    if ! xattr -l "$TARGET_FILE" | grep -q "com.apple.quarantine"; then
      echo "[+] Success: Quarantine attribute removed. Detection should have fired."
    else
      echo "[-] Failure: Quarantine attribute still exists."
    fi
  • Cleanup Commands:

    # Remove the dummy file
    rm /tmp/malicious_payload.txt