North Korea-linked hacker group TraderTraitor launches a new round of attacks using malicious Terraform projects
BlockBeats News, on September 22, according to disclosure from SlowMist, the North Korea-linked threat group TraderTraitor (also known as UNC4899, Jade Sleet) has launched another attack, and recently breached an IT service company based in India that is unrelated to the crypto industry.
The attack ultimately deployed Rust/ARM64 backdoors FLATROOF and ROOFDECK on the victim's macOS device. These two malware families were previously used in the LayerZero attack as well. They have the capabilities to steal credentials and sensitive data, execute shell commands, collect and exfiltrate files, and gain access to cloud services and code repositories.
SlowMist reminds that the attack targets of TraderTraitor are no longer limited to the crypto industry, and attackers may now pay more attention to developers' access to cloud and API services such as AWS, GCP, OVH, and OpenStack.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
JPMorgan: Initiates NexGen Energy (NXE.US) with an “Overweight” rating, optimistic about the Rook I flagship uranium project
JPMorgan has initiated coverage of Canadian uranium miner NexGen Energy (NXE.US) with an "Overweight" rating and a target price of $14.
BlackRock trims Caledonia Mining stake to 6.98% from 7.10%


