FLATROOF is a Rust-based, cross-platform backdoor targeting macOS, Linux, and Windows. Its macOS implementation is also known as Gaslight or macOS.Gaslight, and ARM64 variants have been deployed against Apple Silicon systems. It is used for initial data collection, persistent remote access, and deployment of additional payloads, including the ROOFDECK backdoor. FLATROOF has been used by the North Korean threat actor TraderTraitor, also tracked as Jade Sleet, in compromises involving Web3 organizations and an Indian IT services provider.
FLATROOF supports arbitrary shell-command execution, process enumeration and termination, file management, payload downloads, data uploads, configuration changes, persistence management, and self-removal. Its command-and-control mechanisms include the Telegram Bot API, GitHub API polling, and attacker-controlled HTTP webhooks, with channel availability varying by sample. Persistence mechanisms include Linux services, macOS shell-logout configuration, and Windows Registry Run values. Embedded configuration is encrypted.
Operating-system-specific Python stealers collect browser credentials, session cookies, browsing history, autofill information, command histories, installed applications, process information, and host profiles. Additional targets include Linux keyring material, macOS Safari data and the login keychain, and Windows Credential Manager entries and cryptocurrency-wallet extension data. The Windows collection component injects an embedded executable into a suspended Chromium process to recover browser encryption keys. Collected information is archived for exfiltration. FLATROOF can also remove macOS quarantine attributes from follow-on payloads to bypass Gatekeeper protections.
Observed delivery chains use weaponized Terraform projects and trojanized providers, including infrastructure-engineering assignments presented through fake job interviews. A cross-platform delivery chain uses a Bash loader to select operating-system- and architecture-specific executables concealed as encrypted content within decoy web-font files. Targeting includes DevOps engineers, cryptocurrency and financial-technology developers, and developer endpoints holding cloud credentials or source-control access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The delivered malware is assessed to be FLATROOF, a Rust-based backdoor that supports all three major desktop operating systems.
The operators used this access to install FLATROOF and ROOFDECK backdoors on macOS. FLATROOF was disguised as SystemUpdate and was designed for initial collection and follow-on delivery.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
Each lure contained a manipulated .terraform.lock.hcl file that directed Terraform toward an attacker-controlled provider registry instead of a legitimate source. Running terraform init then downloaded and executed malicious provider modules.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rust-based backdoor for macOS, Linux, and Windows that establishes persistence, gathers system information, lists processes, manages files, executes commands, downloads additional payloads, uploads stolen data, and can remove itself. Its Python-based stealers collect browser credentials, cookies, history, autofill, shell history, and system details. Platform-specific targets include macOS Safari and login keychain data, Windows Credential Manager, and cryptocurrency wallet-extension data. Researchers associated the campaign with suspected TraderTraitor activity without high-confidence attribution.
Malware family combining a Rust backdoor for maintaining access with Python stealers for harvesting sensitive data. The reported delivery chain begins with a malicious Terraform provider that retrieves a Bash loader and deploys payloads tailored to the victim's operating system and CPU architecture. Encrypted executables are concealed in fake .woff font files and extracted using AES-256-CBC decryption.
Named in a post referencing a report about cross-platform malware delivered through a trojanized Terraform provider. The supplied content does not describe FLATROOF's specific capabilities or explicitly establish its relationship to TraderTraitor.
Rust-based backdoor targeting macOS, Linux, and Windows, delivered through a trojanized Terraform provider and a cross-platform Bash loader. Encrypted executables are concealed in decoy font files. FLATROOF supports command execution, system discovery, process and file management, payload delivery, data exfiltration, and platform-specific persistence. Its embedded Python stealers collect browser credentials, cookies, shell history, keychain and credential-store data, and cryptocurrency wallet extension data. Supported C2 channels include Telegram, GitHub, and an attacker-controlled HTTP webhook. The infection chain subsequently deploys ROOFDECK. The report links the campaign to TraderTraitor through targeting and tactical overlap, but explicitly notes insufficient evidence for independent high-confidence attribution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.