TraderTraitor Backdoors Resurface on Victim with No Crypto Ties
Executive Summary
North Korean threat actors used a job‑interview lure that delivered malicious Terraform lock files to a DevOps engineer’s Mac, establishing a foothold and installing the TraderTraitor backdoor. The malware, which can call external APIs, reappears on victims even when they have no cryptocurrency involvement, indicating a broader espionage or sabotage agenda.
Intelligence Metadata - Source Publisher: SentinelOne Labs - Published Date: 2026-09-18T17:00:16+00:00 - Category: malware
Original Description: North Korean operators built a foothold on a DevOps engineer's Mac in a campaign whose job interview lures deliver malware via Terraform lock files.
"The least movement is of importance to all nature. The entire ocean is affected by a pebble."
— Blaise Pascal
Source: SentinelOne Labs