North Korea-linked hacker group TraderTraitor launches a new round of attacks using malicious Terraform projects
BlockBeats News, on September 22, according to disclosure from SlowMist, the North Korea-linked threat group TraderTraitor (also known as UNC4899, Jade Sleet) has launched another attack, and recently breached an IT service company based in India that is unrelated to the crypto industry.
The attack ultimately deployed Rust/ARM64 backdoors FLATROOF and ROOFDECK on the victim's macOS device. These two malware families were previously used in the LayerZero attack as well. They have the capabilities to steal credentials and sensitive data, execute shell commands, collect and exfiltrate files, and gain access to cloud services and code repositories.
SlowMist reminds that the attack targets of TraderTraitor are no longer limited to the crypto industry, and attackers may now pay more attention to developers' access to cloud and API services such as AWS, GCP, OVH, and OpenStack.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Bravo Mining reports Luanga project PFS with after-tax NPV8% of US$1.45 billion
Stonepeak makes equity investment in AMPYR Distributed Energy
Novo Nordisk (NVO.US) Capital Markets Day underwhelms: CEO admits too many commitments, insufficient fulfillment, and the need to rebuild investor confidence
Novo Nordisk CEO Lars Fruergaard Jørgensen said in an interview on Tuesday that the company must make greater efforts to rebuild investor confidence, as its largest drug will face a patent cliff in the early part of the next decade.
