ROOFDECK
malware · malware:roofdeck
Backdoor dropped by FLATROOF, first documented in the April 2026 LayerZero/KelpDAO incident report, that finds its server through a local configuration, an RSA-signed Pastebin dead drop and Nostr profile metadata (Zscaler ThreatLabz and SentinelLabs, 2026-10-08 and 2026-09-18).
Coverage
1
first 2026-09-21 → last 2026-10-09
Latest activity
2026-10-09
SentinelLabs: the same DPRK backdoors from a $292M crypto theft resurface on a victim with no crypto ties, in…
Peak priority
notable
1 notable
Targets
·
no sector or region stated
Sources cited
2
2 hosts
Defender insights
What each entry about ROOFDECK tells a defender to do, newest first.
Triage
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (27 across 11 tactics)
27 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessSupply Chain Compromise: Compromise Software Supply Chain
- ExecutionCommand and Scripting Interpreter: Unix Shell · Command and Scripting Interpreter: Python · User Execution: Malicious File
- PersistenceEvent Triggered Execution: Unix Shell Configuration Modification
- Privilege EscalationProcess Injection: Process Hollowing · Event Triggered Execution: Unix Shell Configuration Modification
- StealthObfuscated Files or Information · Obfuscated Files or Information: Embedded Payloads · Obfuscated Files or Information: Encrypted/Encoded File · Masquerading: Match Legitimate Resource Name or Location · Masquerading: Masquerade File Type · Process Injection: Process Hollowing
- Defense ImpairmentSubvert Trust Controls: Gatekeeper Bypass · Subvert Trust Controls: Code Signing
- Credential AccessSteal Web Session Cookie · Unsecured Credentials: Shell History · Credentials from Password Stores: Keychain · Credentials from Password Stores: Windows Credential Manager
- DiscoverySystem Information Discovery · Browser Information Discovery
- CollectionData from Local System · Clipboard Data · Automated Collection · Archive Collected Data: Archive via Utility
- Command and ControlFallback Channels · Application Layer Protocol: Web Protocols · Web Service: Dead Drop Resolver
- ExfiltrationExfiltration Over Web Service
Initial Access TA0001
T1195.002Supply Chain Compromise: Compromise Software Supply Chain×1
Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
Execution TA0002
T1059.004Command and Scripting Interpreter: Unix Shell×1
Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
T1059.006Command and Scripting Interpreter: Python×1
Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the <code>python.exe</code> interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
T1204.002User Execution: Malicious File×1
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
Persistence TA0003
T1546.004Event Triggered Execution: Unix Shell Configuration Modification×1
Adversaries may establish persistence through executing malicious commands triggered by a user’s shell. User Unix Shells execute several configuration scripts at different points throughout the session based on events. For example, when a user opens a command-line interface or remotely logs in (such as via SSH) a login shell is initiated. The login shell executes scripts from the system (<code>/etc</code>) and the user’s home directory (<code>~/</code>) to configure the environment. All login shells on a system use /etc/profile when initiated. These configuration scripts run at the permission level of their directory and are often used to set environment variables, create aliases, and customize the user’s environment. When the shell exits or terminates, additional shell scripts are executed to ensure the shell exits appropriately.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
Privilege Escalation TA0004
T1055.012Process Injection: Process Hollowing×1
Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses. Process hollowing is a method of executing arbitrary code in the address space of a separate live process.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
T1546.004Event Triggered Execution: Unix Shell Configuration Modification×1
Adversaries may establish persistence through executing malicious commands triggered by a user’s shell. User Unix Shells execute several configuration scripts at different points throughout the session based on events. For example, when a user opens a command-line interface or remotely logs in (such as via SSH) a login shell is initiated. The login shell executes scripts from the system (<code>/etc</code>) and the user’s home directory (<code>~/</code>) to configure the environment. All login shells on a system use /etc/profile when initiated. These configuration scripts run at the permission level of their directory and are often used to set environment variables, create aliases, and customize the user’s environment. When the shell exits or terminates, additional shell scripts are executed to ensure the shell exits appropriately.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
Stealth TA0005
T1027Obfuscated Files or Information×1
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
T1027.009Obfuscated Files or Information: Embedded Payloads×1
Adversaries may embed payloads within other files to conceal malicious content from defenses. Otherwise seemingly benign files (such as scripts and executables) may be abused to carry and obfuscate malicious payloads and content. In some cases, embedded payloads may also enable adversaries to Subvert Trust Controls by not impacting execution controls such as digital signatures and notarization tickets.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
T1027.013Obfuscated Files or Information: Encrypted/Encoded File×1
Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection. Encrypting and/or encoding file content aims to conceal malicious artifacts within a file used in an intrusion. Many other techniques, such as Software Packing, Steganography, and Embedded Payloads, share this same broad objective. Encrypting and/or encoding files could lead to a lapse in detection of static signatures, only for this malicious content to be revealed (i.e., Deobfuscate/Decode Files or Information) at the time of execution/use.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
T1036.005Masquerading: Match Legitimate Resource Name or Location×1
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
T1036.008Masquerading: Masquerade File Type×1
Adversaries may masquerade malicious payloads as legitimate files through changes to the payload's formatting, including the file’s signature, extension, icon, and contents. Various file types have a typical standard format, including how they are encoded and organized. For example, a file’s signature (also known as header or magic bytes) is the beginning bytes of a file and is often used to identify the file’s type. For example, the header of a JPEG file, is <code> 0xFF 0xD8</code> and the file extension is either `.JPE`, `.JPEG` or `.JPG`.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
T1055.012Process Injection: Process Hollowing×1
Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses. Process hollowing is a method of executing arbitrary code in the address space of a separate live process.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
Defense Impairment TA0112
T1553.001Subvert Trust Controls: Gatekeeper Bypass×1
Adversaries may modify file attributes and subvert Gatekeeper functionality to evade user prompts and execute untrusted programs. Gatekeeper is a set of technologies that act as layer of Apple’s security model to ensure only trusted applications are executed on a host. Gatekeeper was built on top of File Quarantine in Snow Leopard (10.6, 2009) and has grown to include Code Signing, security policy compliance, Notarization, and more. Gatekeeper also treats applications running for the first time differently than reopened applications.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
T1553.002Subvert Trust Controls: Code Signing×1
Adversaries may create, acquire, or steal code signing materials to sign their malware or tools. Code signing provides a level of authenticity on a binary from the developer and a guarantee that the binary has not been tampered with. The certificates used during an operation may be created, acquired, or stolen by the adversary. Unlike Invalid Code Signature, this activity will result in a valid signature.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
Credential Access TA0006
T1539Steal Web Session Cookie×1
An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applications and services often use session cookies as an authentication token after a user has authenticated to a website.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
T1552.003Unsecured Credentials: Shell History×1
Adversaries may search the command history on compromised systems for insecurely stored credentials.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
T1555.001Credentials from Password Stores: Keychain×1
Adversaries may acquire credentials from Keychain. Keychain (or Keychain Services) is the macOS credential management system that stores account names, passwords, private keys, certificates, sensitive application data, payment data, and secure notes. There are three types of Keychains: Login Keychain, System Keychain, and Local Items (iCloud) Keychain. The default Keychain is the Login Keychain, which stores user passwords and information. The System Keychain stores items accessed by the operating system, such as items shared among users on a host. The Local Items (iCloud) Keychain is used for items synced with Apple’s iCloud service.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
T1555.004Credentials from Password Stores: Windows Credential Manager×1
Adversaries may acquire credentials from the Windows Credential Manager. The Credential Manager stores credentials for signing into websites, applications, and/or devices that request authentication through NTLM or Kerberos in Credential Lockers (previously known as Windows Vaults).
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
Discovery TA0007
T1082System Information Discovery×1
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
T1217Browser Information Discovery×1
Adversaries may enumerate information about browsers to learn more about compromised environments. Data saved by browsers (such as bookmarks, accounts, and browsing history) may reveal a variety of personal information about users (e.g., banking sites, relationships/interests, social media, etc.) as well as details about internal network resources such as servers, tools/dashboards, or other related infrastructure.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
Collection TA0009
T1005Data from Local System×1
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
T1115Clipboard Data×1
Adversaries may collect data stored in the clipboard from users copying information within or between applications.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
T1119Automated Collection×1
Once established within a system or network, an adversary may use automated techniques for collecting internal data. Methods for performing this technique could include use of a Command and Scripting Interpreter to search for and copy information fitting set criteria such as file type, location, or name at specific time intervals.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
T1560.001Archive Collected Data: Archive via Utility×1
Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration. Many utilities include functionalities to compress, encrypt, or otherwise package data into a format that is easier/more secure to transport.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
Command and Control TA0011
T1008Fallback Channels×1
Adversaries may use fallback or alternate communication channels if the primary channel is compromised or inaccessible in order to maintain reliable command and control and to avoid data transfer thresholds.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
T1071.001Application Layer Protocol: Web Protocols×1
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
T1102.001Web Service: Dead Drop Resolver×1
Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
Exfiltration TA0010
T1567Exfiltration Over Web Service×1
Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.
Evidence: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop · ATT&CK page ↗
Entries about ROOFDECK (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- sentinelone.com1 (50%)
- zscaler.com1 (50%)
All cited sources (2)
- sentinelone.comSentinelOne / SentinelLabshttps://www.sentinelone.com/labs/dont-call-us-well-call-your-apis-tradertraitor-backdoors-resurface-on-victim-with-no-crypto-ties/
- zscaler.comZscaler ThreatLabzhttps://www.zscaler.com/blogs/security-research/suspected-tradertraitor-group-uses-trojanized-terraform-provider-deliver