Loading...
The North Korean hacker group TraderTraitor launched phishing attacks on DevOps and encryption engineers through false job postings on GitHub, and invaded an Indian IT service company. After the victim runs the malicious. terraform.lock.Hcl file, the device is deployed with Rust/ARM64 backdoors FLATROOF and ROOFDECK, which are used to steal credentials, execute shell commands, and gain access to cloud services and code repositories. (Source: SlowMist)