ROOFDECK is a Rust-based backdoor with Windows and macOS variants, including ARM64 builds for Apple Silicon systems. It is deployed as a follow-on implant after attackers establish an initial foothold, often alongside FLATROOF. Its capabilities include arbitrary command execution, interactive and reverse shells, host and process reconnaissance, disk and filesystem discovery, file manipulation, uploads and downloads, encrypted archive creation, data exfiltration, clipboard reading and writing, and background-task management. It also supports persistence management, configuration changes, self-updating, and self-removal. macOS variants establish persistence through LaunchAgents and masquerade as legitimate application or system components.
ROOFDECK uses layered command-and-control discovery to maintain access despite infrastructure changes. It can obtain server information from local configuration, cryptographically signed and encrypted Pastebin records, or attacker-controlled Nostr profile metadata. After resolving its server, it communicates through HTTP or WebSocket endpoints. An embedded RSA public key is used to verify signed operator commands in analyzed macOS variants. Later variants have stripped symbols and debugging information, and have been used to remove earlier implants, reducing forensic evidence.
ROOFDECK has been used by the North Korean TraderTraitor group, also tracked as Jade Sleet and UNC4899, in operations targeting developers and cloud-privileged personnel. Associated campaigns use fraudulent job interviews and infrastructure-engineering assessments hosted in GitHub repositories, with weaponized Terraform projects that retrieve malicious providers. Victims include cryptocurrency and Web3 organizations and an Indian IT services provider whose compromised DevOps workstation had cloud credentials and source-control access. Windows and macOS variants have also been identified in investigations of trojanized Terraform-provider activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The campaign also deploys ROOFDECK, a Windows and macOS backdoor with stronger remote-control functions.
ROOFDECK, masquerading as iSync, offered broader control... The attackers later deployed a stripped ROOFDECK variant called loginwindow, removed the earlier implants, and continued beaconing through June 1.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Each lure contained a manipulated .terraform.lock.hcl file that directed Terraform toward an attacker-controlled provider registry instead of a legitimate source. Running terraform init then downloaded and executed malicious provider modules.
The new ROOFDECK variant removed symbols and debug information to make detection more difficult.
FLATROOF implant ... has been dropped as SystemUpdate ... ROOFDECK, which was deployed as iSync utility.
“ROOFDECK, which uses the Nostr protocol for decentralized command and control.”
FLATROOF... upload[s] files through Telegram... ROOFDECK... resolves command servers through the decentralized Nostr network.
41 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows and macOS backdoor that discovers files and disks, executes shell commands, transfers files, reads and writes clipboard data, manages background tasks, updates itself, and erases traces. It discovers command-and-control servers through local configuration, cryptographically signed Pastebin records, or Nostr profile metadata. Samples are named imagent on macOS and update.exe on Windows. The campaign's suspected TraderTraitor association is not a high-confidence attribution.
Follow-on malware deployed in the reported Terraform supply-chain attack. It discovers command-and-control infrastructure using local settings, signed Pastebin content, and Nostr metadata. The content does not specify its additional capabilities.
Named in a post referencing a report about cross-platform malware delivered through a trojanized Terraform provider. The supplied content does not describe ROOFDECK's specific capabilities or explicitly establish its relationship to TraderTraitor.
Windows and macOS backdoor deployed after FLATROOF in the described infection chain. It resolves its C2 address through local configuration, a signed and encrypted Pastebin record, or Nostr profile metadata that identifies the current Pastebin location. Signature verification prevents unauthorized replacement of the C2 address without the operator's signing key. ROOFDECK communicates over HTTP and WebSockets and supports interactive reverse shells, command execution, host and filesystem discovery, file transfers and manipulation, clipboard access, background tasks, persistence management, configuration changes, updates, and self-destruction. Its association with TraderTraitor is based on campaign overlap rather than independently established high-confidence attribution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.