TraderTraitor Backdoors Resurface on Victim with No Crypto Ties

Executive Summary

North Korean threat actors used a job‑interview lure that delivered malicious Terraform lock files to a DevOps engineer’s Mac, establishing a foothold and installing the TraderTraitor backdoor. The malware, which can call external APIs, reappears on victims even when they have no cryptocurrency involvement, indicating a broader espionage or sabotage agenda.


Intelligence Metadata - Source Publisher: SentinelOne Labs - Published Date: 2026-09-18T17:00:16+00:00 - Category: malware

Original Description: North Korean operators built a foothold on a DevOps engineer's Mac in a campaign whose job interview lures deliver malware via Terraform lock files.

"The least movement is of importance to all nature. The entire ocean is affected by a pebble."

— Blaise Pascal
Source: SentinelOne Labs