Thehackernews Go Malware Campaign Targets Terraform Providers and Go Modules
Article Content
- •Malware distributed via malicious Terraform providers and Go Modules.
- •Linked to the Graphalgo campaign attributed to North Korean actors.
- •Targets are approached through social platforms and job offers, showcasing a sophisticated attack vector.
Cybersecurity researchers have identified a Go-based malware campaign utilizing malicious Terraform providers and Go Modules. The campaign marks the first known instance of malware being distributed through HashiCorp's centralized repository. The affected packages include gocommunity-io/dockerd and kreuzwenker/docker, with the latter being a typosquat of a popular provider. The malware is linked to the Graphalgo campaign attributed to North Korean threat actors and has been reported to overlap with recent malicious npm packages. The malware activates under specific conditions, utilizing a SHA256 hash to decrypt and execute payloads. It features dual command-and-control channels via blockchain and Slack, gathering system information from infected hosts. The attack has been confirmed by multiple cybersecurity firms, including JFrog and CheckMarx, highlighting its targeted nature and sophisticated delivery methods.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track TraderTraitor and Arbitrum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
North Korean Hackers Deploy Mac Backdoors via Fake Job Tests Targeting IT Firms North Korean threat actor Jade Sleet, also known as TraderTraitor, has been linked to a breach of an Indian IT services provider using macOS backdoors named FLATROOF and ROOFDECK. The attack involved social engineering tactics, where fake job interview assignments were used to lure DevOps engineers into executing…
North Korean Fake Worker Scam Targets US Companies North Korean operatives are infiltrating US companies by posing as foreign IT specialists, exploiting trust and business processes to gain legitimate access. These fake workers often secure remote employment under false identities, with reports indicating that they have cost organizations hundreds of millions since…