TraderTraitor-Linked Attack Abuses Terraform Provider to Spread Cross-Platform Malware
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
The TraderTraitor group is conducting a campaign that uses a trojanized Terraform provider to distribute cross-platform malware. The infection chain relies on a Bash loader that selects payloads for macOS, Linux, and Windows before deploying FLATROOF and ROOFDECK malware. These tools focus on data theft, targeting cryptocurrency credentials and browser information while maintaining resilient command-and-control communications.
Investigation
Zscaler ThreatLabz uncovered a malicious Go-based Terraform provider named terraform-provider-awsbeta_v1.0.0 that executes embedded code when loaded. Researchers identified a multi-stage delivery chain involving .woff files disguised as fonts and layered C2 discovery through Pastebin and Nostr metadata. Analysis also confirmed capabilities to bypass macOS Gatekeeper and perform process injection on Windows systems.
Mitigation
Organizations should restrict the use of untrusted Terraform providers and enforce strict validation of provider checksums. Monitoring for unexpected child processes launched by developer tools and CI/CD systems is recommended. Security teams should also restrict outbound connections to unverified domains and monitor unusual file activity within temporary directories to reduce exposure.
Response
When malicious activity is detected, immediately isolate affected developer workstations and CI/CD environments to prevent additional compromise or lateral movement. Conduct a comprehensive forensic investigation to determine the scope of data exfiltration, focusing on browser credentials and cryptocurrency wallets. Rotate all secrets, API keys, and credentials that may have been accessible from compromised systems.
Attack Flow
Detections
Possible Telegram Abuse As Command And Control Channel (via dns_query)
Possible Data Infiltration / Exfiltration / C2 via Third Party Services / Tools (via proxy)
Suspicious Pastebin Domain Communications Attempt (via proxy)
Probable Encryption Or Decryption of Files with OpenSSL [MacOS] (via cmdline)
Possible Base64 Encoded Strings Manipulation [MacOS] (via cmdline)
MacOS Suspicious Tmp Folder File Permissions Modification (via cmdline)
MacOS Suspicious File Was Copied (via cmdline)
Possible Multi-File Staging in TMP Directory for Exfiltration (via file_event)
Archive Was Created In MacOS Temporary Folder (via file_event)
Suspicious Chmod Execution Pointing To Suspicious Directories (via cmdline)
IOCs (HashMd5) to detect: Suspected TraderTraitor Group Uses Trojanized Terraform Provider to Deliver Cross-Platform Malware
ROOFDECK and FLATROOF Command and Control Detection [Windows Network Connection]
MacOS Quarantine Attribute Removal via xattr [Windows Sysmon]
Detection of Safari Updater Bash Script Execution [Linux Process Creation]
Detection of Malicious Safari Updater and Encrypted Payload [Windows Process Creation]
Simulation Execution
-
Attack Narrative & Commands: An attacker has successfully downloaded a malicious payload (e.g.,
payload.dmg) via a web browser. Due to macOS Gatekeeper, the file is flagged with thecom.apple.quarantineattribute. To prevent the user from seeing a “This app was downloaded from the internet” warning and to bypass signature verification checks upon execution, the attacker executes a shell command to strip this attribute. The attacker’s goal is to execute the payload silently to establish a Command and Control (C2) channel. -
Regression Test Script:
#!/bin/bash # Simulation: Remove quarantine attribute to bypass Gatekeeper # 1. Create a dummy file to act as the "malicious" payload TARGET_FILE="/tmp/malicious_payload.txt" touch "$TARGET_FILE" # 2. Simulate the quarantine attribute being present (manually applying it) # Note: In a real scenario, this happens automatically via browser downloads xattr -w com.apple.quarantine "0081;65a12345;Chrome;" "$TARGET_FILE" echo "[+] Simulated quarantine attribute applied to $TARGET_FILE" # 3. Execute the specific command the detection rule is looking for echo "[!] Executing attack command..." /usr/bin/xattr -d com.apple.quarantine "$TARGET_FILE" # 4. Verify if the attribute is gone if ! xattr -l "$TARGET_FILE" | grep -q "com.apple.quarantine"; then echo "[+] Success: Quarantine attribute removed. Detection should have fired." else echo "[-] Failure: Quarantine attribute still exists." fi -
Cleanup Commands:
# Remove the dummy file rm /tmp/malicious_payload.txt