Suspected TraderTraitor Group Uses Trojanized Terraform Provider to Deliver Cross-Platform Malware

    Date: 10/09/2026

    Severity: Medium

    Summary

    In July 2026, ThreatLabz uncovered a supply-chain attack involving a malicious Terraform provider designed to run attacker-controlled code when initialized. The compromised provider retrieves a Bash loader from a Terraform-themed spoofed domain, which deploys tailored malware based on the victim’s operating system and CPU architecture. Attackers conceal encrypted payloads inside fake `.woff` font files, using AES-256-CBC decryption to extract the malicious executables. The FLATROOF malware family combines a Rust-based backdoor with Python stealers to harvest sensitive data and maintain access across compromised systems. The attackers subsequently deploy ROOFDECK, which discovers command-and-control infrastructure through local settings, signed Pastebin content, and Nostr metadata.

    Indicators of Compromise (IOC) List 

    Domains/URLs

    https://diagnose.hashicorp-terraform.io/plugins/grpc/v6/schema/metrics/333afe63-c5a2-43f0-b046-7cbaa7797e8a

    https://supportaru.serveftp.com/statics/cache/v11/

    https://raw.githubusercontent.com/bluearuhost/hospitalrun-frontend/refs/heads/main/public/fonts/version1/

    https://stage-fashion365.vercel.app/static/tinymce4.7.5/plugins/fonts/v1104/

    https://arusupport-region1-webhook.online/statics/cache/v11/abicfjej

    https://pastebin.com/raw/3yptBDhL

    delay.servehttp.com

    Hash

    9d78ece09457907b730d139e4e0c64dd

    73adaea97f003735335505858c1c6def

    116f7189ed7b41f1b339a749d56e63be

    be60c52ca8a01fef7dc15c2f0ebb77d8

    58fa0d651898446d5f5d2ed8a27a3330

    2621753691be9521288664bb551dfba6

    ad0b1b6d2c8b9d09d6473a4a299470ab

    4b8509cde757b5428e5f99c8dffe73ca

    3826dc7a9ba8bd5b1c143560c1530d89

    34a52e6a4d803e94fe497bab682abfd3

    2b81aceab0142472d94eb42e500b27b1

    9d88b4494c7bc27b10358b68a899ad54

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "https://raw.githubusercontent.com/bluearuhost/hospitalrun-frontend/refs/heads/main/public/fonts/version1/" or url like "https://raw.githubusercontent.com/bluearuhost/hospitalrun-frontend/refs/heads/main/public/fonts/version1/" or siteurl like "https://raw.githubusercontent.com/bluearuhost/hospitalrun-frontend/refs/heads/main/public/fonts/version1/" or domainname like "https://diagnose.hashicorp-terraform.io/plugins/grpc/v6/schema/metrics/333afe63-c5a2-43f0-b046-7cbaa7797e8a" or url like "https://diagnose.hashicorp-terraform.io/plugins/grpc/v6/schema/metrics/333afe63-c5a2-43f0-b046-7cbaa7797e8a" or siteurl like "https://diagnose.hashicorp-terraform.io/plugins/grpc/v6/schema/metrics/333afe63-c5a2-43f0-b046-7cbaa7797e8a" or domainname like "https://pastebin.com/raw/3yptBDhL" or url like "https://pastebin.com/raw/3yptBDhL" or siteurl like "https://pastebin.com/raw/3yptBDhL" or domainname like "https://arusupport-region1-webhook.online/statics/cache/v11/abicfjej" or url like "https://arusupport-region1-webhook.online/statics/cache/v11/abicfjej" or siteurl like "https://arusupport-region1-webhook.online/statics/cache/v11/abicfjej" or domainname like "https://supportaru.serveftp.com/statics/cache/v11/" or url like "https://supportaru.serveftp.com/statics/cache/v11/" or siteurl like "https://supportaru.serveftp.com/statics/cache/v11/" or domainname like "delay.servehttp.com" or url like "delay.servehttp.com" or siteurl like "delay.servehttp.com" or domainname like "https://stage-fashion365.vercel.app/static/tinymce4.7.5/plugins/fonts/v1104/" or url like "https://stage-fashion365.vercel.app/static/tinymce4.7.5/plugins/fonts/v1104/" or siteurl like "https://stage-fashion365.vercel.app/static/tinymce4.7.5/plugins/fonts/v1104/"

    Detection Query 2 :

    md5hash IN ("9d78ece09457907b730d139e4e0c64dd","73adaea97f003735335505858c1c6def","9d88b4494c7bc27b10358b68a899ad54","be60c52ca8a01fef7dc15c2f0ebb77d8","2b81aceab0142472d94eb42e500b27b1","116f7189ed7b41f1b339a749d56e63be","58fa0d651898446d5f5d2ed8a27a3330","2621753691be9521288664bb551dfba6","ad0b1b6d2c8b9d09d6473a4a299470ab","4b8509cde757b5428e5f99c8dffe73ca","3826dc7a9ba8bd5b1c143560c1530d89","34a52e6a4d803e94fe497bab682abfd3")

    Reference: 

    Suspected TraderTraitor Group Uses Trojanized Terraform                


    Tags

    PastebinMalwareTrojanSupply chain attackBackdoorLoaderPythonRust Malware

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags