Hackers hid RAT in Terraform provider and targeted programmers

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
548
Reaction score
951
Deposit
0$
The infrastructure code turned out to be a convenient trap for the working machines of the developers. Aikido found malicious code in two Terraform providers and two Go modules. The company considers the finding to be the first known case of systematic distribution of malware through Terraform Registry.





The providers of gocommunity-io/dockerd and kreuzwenker/docker, published in early September, were dangerous. The second simulates the popular kreuzwerker/docker, which has about 56 million downloads. Terraform provider is a plugin through which Terraform manages external services, so such a component is launched directly on the developer’s machine or in the CI/CD environment.





Malicious logic almost does not give itself at the usual check. The code in both providers is triggered only when the SHA-256 from the combined values of the containerName and networkID coincides with the predefined hash. After the coincidence, the program decrypts the path to the hidden archive, extracts the contents, decrypts files through AES and launches the received Go code by a separate team.





In the second stage, RAT is loaded, that is, a remote access trojan. The program collects information about the operating system, architecture, computer name, user and availability of Node.js, after which it communicates with the control infrastructure. Commands come through two independent channels through Slack and a smart contract on the Arbitrum Sepolia test network, and can then run additional code in Go or JavaScript.












This scheme makes it difficult to analyze. RAT interviews blockchain about once every three seconds, and Slack once every ten seconds, with messages encrypted with separate keys for infected customers. In a regular sandbox, the provider may not show malicious behavior at all if the inspecting party does not reproduce the desired launch parameters.





In parallel, the attackers distributed the same code through Go-modules gocommunity.io/orderedbtree and gogets.dev/btreex. In the second case, the archive was disguised as a SQL file, and the launch was also tied to a special input value. The authors of the campaign forged the dates of the commits, so part of the history of the project looked older than the real publication of the package in September.





For disguise, operators created gocommunity[.]io and gogets[.]dev domains that depicted new Go package ecosystems. Similar tactics have already covered npm, PyPI, Go Modules and other sites where malicious dependencies were given as conventional development tools. The new domains, according to Aikido, had to increase the credibility of fake packages.





Traces of infrastructure and a common public key link new samples to the Graphalgo campaign. ReversingLabs in February tied Graphalgo with the North Korean Lazarus Group, which lured developers with fictitious vacancies and test assignments. Aikido talks about the technical intersection of new packages with this campaign, not the self-attribution of each episode.





In the open messages of the manager of the Slack channel Aikido allocated 18 unique host names. Among them are three Windows machines, five Linux systems and ten macOS computers. The scale looks limited, and the selective launch conditions indicate rather a point operation. Previously, the intruders have already replaced Terraform modules through the compromised infrastructure of the Coder.





Aikido advises to consider compromised the entire machine or CI/CD performer, where any of the four components were launched. The company recommends isolating the system, replacing the associated GitHub, GitLab and package registry tokens, cloud credentials and SSH keys, checking your action history, removing malicious dependencies, and reinstalling the system, as simply removing the package is not enough.
 
Top Bottom