TraderTraitor Backdoors Found on an IT Services Provider’s Mac

· Original article ↗

Summary

SentinelOne found TraderTraitor’s FLATROOF and ROOFDECK backdoors on an Indian IT services provider’s Mac and identified fake job-interview projects using malicious Terraform provider lock files. The infection route for this victim remains unproven.

Key points

  • The victim was an Indian IT services provider with no cryptocurrency ties; telemetry identified one affected Apple Silicon Mac belonging to a DevOps engineer.
  • Researchers found weaponized Terraform lock files in fake coding-project repositories used in job-interview lures. Running `terraform init` with a malicious provider could download and execute attacker-controlled code.
  • SentinelOne could not confirm how the backdoors reached this victim’s Mac; both were present by March 18, 2026, and began running on March 29.
  • The Rust-based macOS backdoors, FLATROOF and ROOFDECK, can collect system and browser data, command histories, and the login keychain; ROOFDECK also supports remote commands, file transfer, reconnaissance, and persistence.
  • A later ROOFDECK version beaconed to a new command-and-control server until June 1; the binary was moved to Trash on June 17.
  • SentinelOne recommends monitoring developer endpoints for unsigned binaries and suspicious IDE child processes, and checking Terraform provider sources before running unfamiliar projects.

Article Details

Attack Vectors
  • TraderTraitor used fake job interviews to direct developers to coding projects containing weaponized Terraform lock files.
  • The lock files specified custom providers hosted on attacker-controlled, typosquatted registry domains. Running terraform init downloaded and executed the malicious provider modules.
  • In the additional victim's case, telemetry established that both backdoors were present by 2026-03-18, but did not establish how they were delivered. Cursor launched them when a development workspace was opened on 2026-03-29.
  • According to the LayerZero Labs report, the attackers installed the backdoors after an employee installed a weaponized interview project on a company workstation.
Defensive Notes
  • Prioritize endpoint monitoring for engineers with cloud permissions and source-control access. Investigate unsigned binaries running from home directories, unexpected IDE child processes, and outbound TLS from either.
  • Follow up on unsolicited coding repositories and interview assignments; consider restricting external job interviews on corporate workstations.
  • Before running a Terraform project with an included .terraform.lock.hcl file, verify its provider registries and investigate package sources, including packages on the official registry.
  • Train developers with sensitive access to recognize typosquatted provider domains and the risks of running projects of unknown origin.

Indicators of compromise

TypeIndicatorContext
DOMAINanesthesiaschool[.]comListed among domains associated with the custom certificate's 'ub' user metadata; C2 use was not established.
DOMAINgalaxy-royal[.]onlineListed among domains associated with the custom certificate's 'ub' user metadata; C2 use was not established.
DOMAINgrenight[.]comROOFDECK command-and-control domain used by the later loginwindow binary.
DOMAINheyhay[.]onlineListed among domains associated with the custom certificate's 'ub' user metadata; C2 use was not established.
DOMAINmactroubleshoots[.]proListed among domains associated with the custom certificate's 'ub' user metadata; C2 use was not established.
DOMAINregistry[.]hashicorp-aws[.]comAttacker-controlled Terraform provider registry specified by weaponized lock files.
DOMAINregistry[.]hashicorp-aws[.]ioAttacker-controlled Terraform provider registry specified by weaponized lock files.
DOMAINregistry[.]hashicorp-terraform[.]ioAttacker-controlled Terraform provider registry specified by weaponized lock files.
DOMAINstorage[.]hubpage[.]cloudROOFDECK command-and-control domain.
DOMAINtechnicais[.]sytes[.]netFLATROOF command-and-control domain.
DOMAINtinklify[.]comListed among domains associated with the custom certificate's 'ub' user metadata; C2 use was not established.
DOMAINvaimage[.]comListed among domains associated with the custom certificate's 'ub' user metadata; C2 use was not established.
HOSTNAME185-66-91-112[.]cprapid[.]comListed among domains associated with the custom certificate's 'ub' user metadata; C2 use was not established.
HOSTNAME213-111-146-132[.]cprapid[.]comListed among domains associated with the custom certificate's 'ub' user metadata; C2 use was not established.
HOSTNAMEapp[.]heyhay[.]onlineListed among domains associated with the custom certificate's 'ub' user metadata; C2 use was not established.
HOSTNAMEdela[.]servehttp[.]comListed among domains associated with the custom certificate's 'ub' user metadata; C2 use was not established.
HOSTNAMEgame[.]galaxy-royal[.]onlineListed among domains associated with the custom certificate's 'ub' user metadata; C2 use was not established.
HOSTNAMEmx01[.]galaxy-royal[.]onlineListed among domains associated with the custom certificate's 'ub' user metadata; C2 use was not established.
HOSTNAMEns4[.]galaxy-royal[.]onlineListed among domains associated with the custom certificate's 'ub' user metadata; C2 use was not established.
HOSTNAMEupdate[.]heyhay[.]onlineListed among domains associated with the custom certificate's 'ub' user metadata; C2 use was not established.
HOSTNAMEwss[.]sytes[.]netListed among domains associated with the custom certificate's 'ub' user metadata; C2 use was not established.
HOSTNAMEwww[.]anesthesiaschool[.]comListed among domains associated with the custom certificate's 'ub' user metadata; C2 use was not established.
HOSTNAMEwww[.]freehealth[.]latListed among domains associated with the custom certificate's 'ub' user metadata; C2 use was not established.
HOSTNAMEwww[.]heyhay[.]onlineListed among domains associated with the custom certificate's 'ub' user metadata; C2 use was not established.
HOSTNAMEwww[.]mactroubleshoots[.]proListed among domains associated with the custom certificate's 'ub' user metadata; C2 use was not established.
HOSTNAMEwww[.]tinklify[.]comListed among domains associated with the custom certificate's 'ub' user metadata; C2 use was not established.
IPV4176[.]97[.]114[.]232FLATROOF command-and-control IP associated with technicais.sytes[.]net.
IPV445[.]11[.]59[.]140ROOFDECK command-and-control IP associated with storage.hubpage[.]cloud.
IPV485[.]137[.]56[.]10Server from which ROOFDECK staged the later loginwindow payload.
IPV485[.]137[.]56[.]245ROOFDECK command-and-control IP associated with grenight[.]com.
SHA102df07a173ab03b82a4fb6a08973fff8b1467f28FLATROOF backdoor binary identified as SystemUpdate.
SHA14ad92bf92ee614b05c340ce17bef7b6ef5a25e82SHA-1 fingerprint of the custom certificate identified for ROOFDECK TLS communication.
SHA15728b11d30586bbfc1d8bd12df1c722a06e767a2Stripped ROOFDECK backdoor binary identified as loginwindow.
SHA1c491d477dbe0ae04e9aed9dbe237144c03f73ec4ROOFDECK backdoor binary identified as iSync.
SHA2564b2d3e8ccce8920a6d01e7d02b84236545a20e5f754b3eec253f8b416b731daaSHA-256 fingerprint of the custom certificate identified for ROOFDECK TLS communication.
URLhxxps[:]//github[.]com/chainstacker/Northwind-IAC/blob/930e5be6d34511bedbfb0d762bd08fffe64e9630/aws/us-east-1/prod/northwind/global/vpc/[.]terraform[.]lock[.]hclSpecific GitHub file identified as a weaponized Terraform lock file.
URLhxxps[:]//github[.]com/exubient0/terraform-candidate-repo/blob/main/[.]terraform[.]lock[.]hclSpecific GitHub file identified as a weaponized Terraform lock file.
URLhxxps[:]//github[.]com/radupopa369/gtn-candidate-repo/blob/feat/three-tier-infrastructure/live/[.]terraform[.]lock[.]hclSpecific GitHub file identified as a weaponized Terraform lock file.
URLhxxps[:]//github[.]com/RyanLRay/Technical-Assessments/blob/19af09ebe8b7ad03419677dda515507dd099bc39/README[.]md?plain=1#L175Specific coding-challenge README reference to a weaponized Terraform provider domain.
URLhxxps[:]//github[.]com/Steed-LHV/assessmentCoding-challenge repository listed as containing README references to a weaponized Terraform provider domain.

MITRE ATT&CK

T1036.005 · Match Legitimate Resource Name or LocationBackdoor binaries used names resembling macOS components, including SystemUpdate, iSync, and loginwindow.T1057 · Process DiscoveryFLATROOF's harvesting module collected a running-process snapshot using ps aux; ROOFDECK also supports process listing.T1070.004 · File DeletionAfter the later ROOFDECK version began beaconing, the attackers used it to delete the original FLATROOF and ROOFDECK binaries.T1071.001 · Web ProtocolsROOFDECK polled an HTTPS /app_version endpoint for signed, encrypted commands.T1082 · System Information DiscoveryFLATROOF collected a system hardware and software profile using system_profiler.T1102.001 · Dead Drop ResolverROOFDECK searched Nostr profiles for an operator-controlled website field containing its C2 URL.T1105 · Ingress Tool TransferROOFDECK retrieved a later loginwindow payload from a staging server and supports downloading additional files.T1115 · Clipboard DataROOFDECK supports reading and writing the macOS clipboard, including potentially copied secrets.T1204.002 · Malicious FileFake interview projects induced developers to run Terraform with a weaponized lock file, causing malicious provider modules to execute.T1543.001 · Launch AgentROOFDECK installed a plist in ~/Library/LaunchAgents with RunAtLoad enabled for persistence.T1553.001 · Gatekeeper BypassFLATROOF removed the com.apple.quarantine attribute from ROOFDECK and set its executable bit so it could run without a Gatekeeper prompt.T1567 · Exfiltration Over Web ServiceFLATROOF's harvesting module exfiltrated collected data using a Telegram bot token and file-attachment mechanism.

Threat Actors

Malware

Products

Countries

Industries

Related Articles