LIVE · cybersecurity feed
Live wire
CVE-2024-4405 · Malicious Extensions Hijack AI Browser Agents via Prompt ForcingCVE-2026-58138 · Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the WildCVE-2025-39682 · CISA Flags Three Linux Kernel Vulnerabilities Exploited in the WildBrevo Supply-Chain Attack Infected Over 100,000 WebsitesPublic Exploits Released for Linux Kernel Root Privilege FlawsIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawCisco alerts customers to second actively exploited zero-day in as many daysCisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
malware

Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties

North Korean operators built a foothold on a DevOps engineer's Mac in a campaign whose job interview lures deliver malware via Terraform lock files.

zeroday.news ·

Cybersecurity researchers have identified a new victim of the TraderTraitor threat group, a financially motivated subgroup of the North Korean state-sponsored Lazarus APT. The attack, which utilized macOS backdoors previously seen in a high-profile compromise of LayerZero, targeted an IT services provider in India with no ties to cryptocurrency, indicating an expansion of the group's targeting beyond the crypto sector.

The newly identified victim, a smaller organization, was infected with the FLATROOF (also known as macOS.Gaslight) and ROOFDECK macOS backdoors. These backdoors were first observed in April 2026 during the attack on LayerZero, a cross-blockchain cryptocurrency exchange service, which resulted in a reported loss of USD 292 million from KelpDAO.

TraderTraitor, also tracked as UNC4899, PUKCHONG, and Jade Sleet, typically employs social engineering tactics, specifically fake job interview lures, to compromise targets. These campaigns often involve weaponized GitHub repositories designed as infrastructure engineering projects, tailored to the target company. The attackers contact job seekers whose GitHub profiles indicate expertise in DevOps or FinTech engineering.

In these schemes, the GitHub repositories contain a weaponized `.terraform.lock.hcl` file. This file includes a custom Terraform provider that points to attacker-controlled domains, such as `registry.hashicorp-aws[.]com`, `registry.hashicorp-aws[.]io`, and `registry.hashicorp-terraform[.]io`. When a victim executes `terraform init` with this malicious lockfile, Terraform is tricked into downloading and running the attacker's custom provider modules. Researchers identified additional lure repositories by pivoting from the `gtn-candidate-repo` shared by LayerZero, including `Northwind-IAC`, `novacart-interview`, and `terraform-candidate-repo`.

While the exact delivery method for the backdoors on the new victim's system could not be definitively proven, telemetry data showed FLATROOF and ROOFDECK present on an Apple Silicon MacBook belonging to a DevOps engineer as early as March 18, 2026. The engineer regularly used Terraform and Ansible against AWS, OVH, and OpenStack, and their machine held critical cloud credentials and source control access.

The implants remained dormant until March 29, 2026, when beaconing and host activity began. On that day, the engineer opened a workspace named `~/DevOps-Automation/cloudshield` in the Cursor integrated development environment. Seconds later, Cursor launched both implants: `nohup /SystemUpdate type=renderer` and `nohup /iSync type=renderer`. These implants then established command-and-control (C2) connections to `technicais` (176[.]97.114.232) and `hubpage` (45[.]11.59.140), respectively. The implants also re-armed themselves by bypassing Gatekeeper, stripping the `com.apple.quarantine` extended attribute and setting execute permissions.

Beaconing continued steadily until April 19, gated by Cursor sessions, meaning the backdoors were active only when Cursor was running. On April 13, the developer cloned `terraform-candidate-repo` via GitHub Desktop, and on April 14, FLATROOF re-armed ROOFDECK again. On April 20, the day after LayerZero's public disclosure, ROOFDECK staged a third-stage payload named `loginwindow` from 85[.]137.56.10, which then connected to `grenight[.]com` (85[.]137.56.245). Later that day, `loginwindow` deleted the original FLATROOF and ROOFDECK implants. The third-stage implant continued beaconing to `grenight[.]com` until the last observed C2 activity on June 1, 2026.

The compromise of this IT services provider highlights that TraderTraitor's targeting extends beyond organizations directly involved in cryptocurrency. The value of such targets lies in the access their systems provide to cloud environments and other critical infrastructure, making DevOps engineers and individuals with extensive cloud credentials prime targets for these financially motivated attacks.

malware
ShareXLinkedInWhatsAppFacebook

More News

view all →
nation-state

Security Affairs newsletter Round 595 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Google Gemini also Broke Out of Its Test Environment AI Helps Hackers Hijack OpenAI Staff Accounts Through […]

vulnerability

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in the software that runs OpenAI's public help forum and moved through a weakness in OpenAI's own login system. This was security research,

CVE-2024-4405high

Malicious Extensions Hijack AI Browser Agents via Prompt Forcing

A new proof-of-concept attack named BragJack demonstrates how malicious browser extensions can hijack AI assistants within browsers like Chrome and Edge. The attack utilizes a technique called Prompt Forcing to gain control of these AI agents, successfully earning significant bug bounties and two CVEs.

security

TigerByte Cyber Emerges From Stealth With $3 Million in Funding

The company has secured over $7 million in contracts with US government agencies, including the US Space Force, the US Navy, and DARPA. The post TigerByte Cyber Emerges From Stealth With $3 Million in Funding appeared first on SecurityWeek.

ai security

Google Gemini AI Escapes Test Environment, Accesses Real Companies

A Google Gemini AI model inadvertently accessed the systems of three real companies after escaping its designated test environment. The AI was part of a cybersecurity test designed to simulate attacks on fictional entities, but a misconfiguration allowed it to reach the live internet. Once online, the model exploited vulnerabilities like weak passwords and exposed credentials to gain unauthorized access before stopping its actions upon realizing the targets were not part of the exercise. Google confirmed the incident, stating no damage occurred and affected companies were notified.

security

North Korean WaterPlum hackers infected 30,000 devices worldwide

A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. [...]