Suspected TraderTraitor Hackers Trojanize Terraform Provider to Deploy Cross-Platform Malware
What happened
ThreatLabz found similarities in targeting, tooling, and tactics but lacked unique code matches, shared infrastructure, or cryptographic evidence […] The post Suspected TraderTraitor Hackers Trojanize Terraform Provider to Deploy Cross-Platform Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform . ThreatLabz found similarities in targeting, tooling, and tactics but lacked unique code matches, shared infrastructure, or cryptographic evidence sufficient for independent, high-confidence attribution.
The initial delivery mechanism for the analyzed provider also remains unresolved. A campaign in July 2026 using a trojanized Terraform provider to deploy cross-platform malware (software written to damage a system or steal from it) against developer environments.
The operation delivers FLATROOF for credential theft and initial access, followed by ROOFDECK for broader remote control. cyber security Cyber Security News Malware 3 min.
Read Suspected TraderTraitor Hackers Trojanize Terraform Provider to Deploy Cross-Platform Malware By Mayura Kathir October 9, 2026 Share Facebook Twitter Pinterest WhatsApp A campaign in July 2026 using a trojanized Terraform provider to deploy cross-platform malware against developer environments. The Go binary, terraform-provider-awsbeta_v1.0.0 , impersonates an AWS Terraform provider while retaining a functional provider scaffold. The implant checks for session.lock in the temporary directory before downloading a Bash loader from hashicorp-terraform[.]io .
Key facts
- ThreatLabz — found: similarities in targeting, tooling, and tactics but lacked unique code matches, shared infrastructure, or cryptographic evidence […] The post Suspected TraderTraitor Hackers Trojanize Terraform Provider to Deploy Cross-Platform Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform
- ThreatLabz — found: similarities in targeting, tooling, and tactics but lacked unique code matches, shared infrastructure, or cryptographic evidence sufficient for independent, high-confidence attribution
Sources & evidence
- GBHackers Reporting source
Suspected TraderTraitor Hackers Trojanize Terraform Provider to Deploy Cross-Platform Malware ↗
https://gbhackers.com/terraform-supply-chain/