Date: 10/09/2026
Severity: Medium
Summary
In July 2026, ThreatLabz uncovered a supply-chain attack involving a malicious Terraform provider designed to run attacker-controlled code when initialized. The compromised provider retrieves a Bash loader from a Terraform-themed spoofed domain, which deploys tailored malware based on the victim’s operating system and CPU architecture. Attackers conceal encrypted payloads inside fake `.woff` font files, using AES-256-CBC decryption to extract the malicious executables. The FLATROOF malware family combines a Rust-based backdoor with Python stealers to harvest sensitive data and maintain access across compromised systems. The attackers subsequently deploy ROOFDECK, which discovers command-and-control infrastructure through local settings, signed Pastebin content, and Nostr metadata.
Indicators of Compromise (IOC) List
Domains/URLs | https://diagnose.hashicorp-terraform.io/plugins/grpc/v6/schema/metrics/333afe63-c5a2-43f0-b046-7cbaa7797e8a https://supportaru.serveftp.com/statics/cache/v11/ https://raw.githubusercontent.com/bluearuhost/hospitalrun-frontend/refs/heads/main/public/fonts/version1/ https://stage-fashion365.vercel.app/static/tinymce4.7.5/plugins/fonts/v1104/ https://arusupport-region1-webhook.online/statics/cache/v11/abicfjej https://pastebin.com/raw/3yptBDhL delay.servehttp.com |
Hash | 9d78ece09457907b730d139e4e0c64dd
73adaea97f003735335505858c1c6def
116f7189ed7b41f1b339a749d56e63be
be60c52ca8a01fef7dc15c2f0ebb77d8
58fa0d651898446d5f5d2ed8a27a3330
2621753691be9521288664bb551dfba6
ad0b1b6d2c8b9d09d6473a4a299470ab
4b8509cde757b5428e5f99c8dffe73ca
3826dc7a9ba8bd5b1c143560c1530d89
34a52e6a4d803e94fe497bab682abfd3
2b81aceab0142472d94eb42e500b27b1
9d88b4494c7bc27b10358b68a899ad54
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "https://raw.githubusercontent.com/bluearuhost/hospitalrun-frontend/refs/heads/main/public/fonts/version1/" or url like "https://raw.githubusercontent.com/bluearuhost/hospitalrun-frontend/refs/heads/main/public/fonts/version1/" or siteurl like "https://raw.githubusercontent.com/bluearuhost/hospitalrun-frontend/refs/heads/main/public/fonts/version1/" or domainname like "https://diagnose.hashicorp-terraform.io/plugins/grpc/v6/schema/metrics/333afe63-c5a2-43f0-b046-7cbaa7797e8a" or url like "https://diagnose.hashicorp-terraform.io/plugins/grpc/v6/schema/metrics/333afe63-c5a2-43f0-b046-7cbaa7797e8a" or siteurl like "https://diagnose.hashicorp-terraform.io/plugins/grpc/v6/schema/metrics/333afe63-c5a2-43f0-b046-7cbaa7797e8a" or domainname like "https://pastebin.com/raw/3yptBDhL" or url like "https://pastebin.com/raw/3yptBDhL" or siteurl like "https://pastebin.com/raw/3yptBDhL" or domainname like "https://arusupport-region1-webhook.online/statics/cache/v11/abicfjej" or url like "https://arusupport-region1-webhook.online/statics/cache/v11/abicfjej" or siteurl like "https://arusupport-region1-webhook.online/statics/cache/v11/abicfjej" or domainname like "https://supportaru.serveftp.com/statics/cache/v11/" or url like "https://supportaru.serveftp.com/statics/cache/v11/" or siteurl like "https://supportaru.serveftp.com/statics/cache/v11/" or domainname like "delay.servehttp.com" or url like "delay.servehttp.com" or siteurl like "delay.servehttp.com" or domainname like "https://stage-fashion365.vercel.app/static/tinymce4.7.5/plugins/fonts/v1104/" or url like "https://stage-fashion365.vercel.app/static/tinymce4.7.5/plugins/fonts/v1104/" or siteurl like "https://stage-fashion365.vercel.app/static/tinymce4.7.5/plugins/fonts/v1104/" |
Detection Query 2 : | md5hash IN ("9d78ece09457907b730d139e4e0c64dd","73adaea97f003735335505858c1c6def","9d88b4494c7bc27b10358b68a899ad54","be60c52ca8a01fef7dc15c2f0ebb77d8","2b81aceab0142472d94eb42e500b27b1","116f7189ed7b41f1b339a749d56e63be","58fa0d651898446d5f5d2ed8a27a3330","2621753691be9521288664bb551dfba6","ad0b1b6d2c8b9d09d6473a4a299470ab","4b8509cde757b5428e5f99c8dffe73ca","3826dc7a9ba8bd5b1c143560c1530d89","34a52e6a4d803e94fe497bab682abfd3")
|
Reference:
Suspected TraderTraitor Group Uses Trojanized Terraform