At a Glance
| Attribute | Details |
|---|---|
| Actor or Group | TraderTraitor (aka UNC4899, Jade Sleet, PUKCHONG) |
| Activity Type | Fake job recruitment, supply chain compromise, credential theft |
| Targets or Victims | IT services providers and cryptocurrency developers |
| Scale | Claimed USD 292 million stolen in prior intrusion; single IT endpoint in new incident |
| Jurisdiction / Status | Suspected North Korean state-sponsored threat group; uncharged |
| Source | SentinelOne Threat Labs |
Executive Summary
SentinelOne discovered that North Korean threat actors deployed the new TraderTraitor macOS backdoors against an enterprise outside the cryptocurrency industry. The operators used deceptive job interview coding tasks to deliver malicious infrastructure automation code. Consequently, the intrusion compromised a developer workstation containing production cloud access keys.
Deceptive Recruitment and Weaponized Terraform
The campaign relied on social engineering lures known as Contagious Interview schemes. Specifically, attackers contacted software engineers on social media under the pretense of hiring for technical roles. The threat actors directed candidates to GitHub repositories containing infrastructure coding assessments. These project repositories impersonated startup companies named Northwind and Novacart.
Each repository carried a weaponized dependency lockfile. Specifically, the file pointed Terraform to rogue provider registries hosted on domains like registry.hashicorp-aws[.]com. When an applicant ran initialization commands, the tool pulled malicious modules directly from attacker infrastructure. As SentinelOne explained, “When the victim runs terraform init with the weaponized lockfile in place, Terraform treats the custom provider as the source of truth, resulting in Terraform downloading and executing the malicious provider modules.”

Once unpacked, the malicious provider installed two custom macOS backdoors onto the host machine. The files remained dormant on disk for eleven days before initiating active operations. The implants activated only after the developer opened a specific automation project inside the Cursor source code editor. Cursor then executed integrated terminal shells that launched the background implants.
Attribution to North Korean Cyber Actors
SentinelOne attributes this operation to the DPRK-nexus group TraderTraitor with high confidence. Industry researchers also track this suspected state-sponsored cybercrime group under names such as UNC4899, Jade Sleet, and PUKCHONG. The group operates as an active unit within the broader Lazarus cluster.
Historically, TraderTraitor focused almost exclusively on cryptocurrency exchanges and decentralized finance protocols. In April 2026, the group breached LayerZero Labs to trigger a fraudulent minting event against KelpDAO. That attack resulted in the theft of an estimated USD 292 million. Independent incident reporting by LayerZero Labs and Mandiant confirmed identical backdoor variants in that breach. Therefore, finding these tools inside an unrelated IT firm reveals a significant shift in operational targeting.
Analysis of the Dual macOS Backdoors
The attackers deployed two distinct ARM64 backdoors written in Rust named FLATROOF and ROOFDECK. The first implant, FLATROOF, operates as an initial reconnaissance tool disguised as a system update. Immediately upon startup, FLATROOF clears security quarantine attributes from the secondary implant. This action bypasses Apple Gatekeeper controls without presenting an authorization prompt to the user.
Next, FLATROOF executes an embedded Python module to gather host credentials. The module harvests browser histories from Safari, Chrome, Brave, and Firefox. It also extracts command terminal histories, process lists, and the local login keychain database. The implant then exfiltrates these stolen files to the attacker through an integrated Telegram bot.
Decentralized Command Channels via Nostr
The second implant, ROOFDECK, acts as a command module with broader lateral capabilities. The backdoor reads an encrypted local configuration file to configure its connection settings. Interestingly, the tool queries public Nostr relays to discover its command-and-control server. The implant searches for the operator’s public Nostr profile and reads the website field to establish a live communication address.
Furthermore, ROOFDECK verifies command integrity using an embedded RSA public key before running tasks. The implant executes file system commands, captures clipboard data, and downloads additional toolkits. The authors used custom certificates generated via mkcert, which inadvertently exposed an internal testing environment username. Later, the operators deployed an updated binary named loginwindow to delete the earlier implants and erase forensic traces.
However, the attackers found little strategic value in the compromised Indian IT services firm. SentinelOne observed, “Our investigation revealed insights into what happens when this threat actor compromises a smaller organization that we believe ultimately yielded insufficient value to sustain the intrusion.” After several weeks of intermittent beaconing, the attackers abandoned the machine and moved the payload to the system trash.
Defense and Detection Guidance
This incident demonstrates that any organization employing DevOps engineers faces serious supply chain risks. Because engineers manage cloud credentials, their workstations represent valuable gateways into production environments. Therefore, security teams must monitor developer devices for unusual background processes and unexpected shell spawns.
Organizations should audit Terraform configuration files and dependency lockfiles for untrusted provider registries. Administrators must prevent tools from fetching modules from unverified third-party domains. Furthermore, security teams should inspect outbound network traffic for abnormal connections to Nostr relays and external Telegram bots. For full technical details and indicators, read the SentinelOne report on TraderTraitor macOS backdoors. Implementing strict code signing checks and endpoint behavioral monitoring will help organizations block malicious recruitment lures.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!