Back to Intelligence

FLATROOF/ROOFDECK Trojanized Terraform Campaign, ARTEX Agentic-AI Attacks & AWS Bedrock Credential Testing: OTX Pulse Analysis — Enterprise Detection Pack

SA
Security Arsenal Team
October 9, 2026
9 min read

Three concurrent OTX pulses paint a coherent picture of a credential-theft and developer-targeting ecosystem that has matured well beyond simple infostealer logs. Security teams are now facing adversaries who weaponize the toolchain (Terraform providers), the AI stack (agentic pentest frameworks and commercial LLMs), and the cloud control plane (AWS Bedrock) in a single operational tempo.

The first pulse, attributed to the suspected DPRK-nexus TraderTraitor group, describes a July 2026 campaign uncovered by Zscaler ThreatLabz in which a trojanized Terraform provider impersonating HashiCorp infrastructure delivers the cross-platform malware families FLATROOF and ROOFDECK to cryptocurrency and Web3 developers. The attack chain begins when a developer initializes a project referencing the malicious provider; the provider reaches out to a HashiCorp-themed lookalike domain (hashicorp-terraform.io, with a diagnose. subdomain) and pulls a Bash loader that fingerprints the host operating system before deploying the OS-appropriate payload. Objective: theft of wallet keys, cloud credentials, and developer identity material from technology and finance sector engineers.

The second pulse documents an unidentified, likely Chinese-speaking financially motivated actor using ARTEX — a Chinese-developed open-source agentic penetration testing framework — against South Korean financial institutions between late September and early October 2026. The actor chained ARTEX with commercial LLMs (DeepSeek v4.1-flash, GLM-5) to autonomously plan and execute intrusion stages, and successfully exfiltrated data. This is among the first confirmed OTX-tracked cases of LLM-orchestrated post-exploitation producing confirmed data theft.

The third pulse (Datadog Security Labs) closes the loop: harvested AWS credentials are now being systematically validated against Amazon Bedrock by credential-harvesting platforms including KMON_NOC. Attackers call GetCallerIdentity to confirm key validity, then ListFoundationModels and model-invocation calls to determine whether the stolen key can access Anthropic Claude and other foundation models — enabling LLM resource theft (token-jacking), fraud, and laundering of AI compute through victim cloud bills.

Collectively: credentials stolen by FLATROOF/ROOFDECK-style malware are being validated and monetized by platforms like KMON_NOC, while AI tooling like ARTEX accelerates the exploitation phase. Developer workstations and cloud identity are the convergent target.

Threat Actor / Malware Profile

TraderTraitor — FLATROOF / ROOFDECK

  • Distribution: Trojanized Terraform provider published/referenced via a HashiCorp-themed lookalike domain (hashicorp-terraform.io). Social engineering leverages developer trust in infrastructure-as-code supply chains; the nostr tag suggests lure or C2-adjacent use of the Nostr protocol for resilient communications.
  • Payload behavior: The provider downloads a Bash loader from delay.servehttp.com / diagnose.hashicorp-terraform.io, fingerprints the OS, and deploys platform-specific FLATROOF or ROOFDECK binaries targeting macOS, Linux, and Windows developer hosts.
  • C2 communication: HTTPS to attacker-controlled lookalike domains and webhook infrastructure (arusupport-region1-webhook.online), blending with legitimate dev-tool traffic patterns.
  • Persistence: Typically established through developer-context mechanisms — shell profile injection, launch agents on macOS, or scheduled tasks — granting survival across reboots while remaining inside the trusted developer workflow.
  • Anti-analysis: OS-conditional payload delivery (sandbox mismatch evades detonation), legitimate-tool masquerading (HashiCorp branding), and staged loading that keeps the final payload off disk until environmental checks pass.

ARTEX (agentic AI intrusion framework)

  • Distribution: Operator-deployed post-initial-access; ARTEX is an open-source agentic pentest tool driven by LLM reasoning loops (DeepSeek, GLM-5) that autonomously select exploitation and lateral movement steps.
  • Payload behavior: Autonomous reconnaissance, vulnerability exploitation, and exfiltration against South Korean financial networks; the LLM planner adapts to defender responses in near-real-time.
  • C2: Observed across a distributed IPv4 infrastructure set (38.244.50.120, 101.53.80.20, 205.214.59.31, and others listed below), consistent with rented VPS / bulletproof hosting.

KMON_NOC and Bedrock credential validators

  • Behavior: Automated pipelines take stolen AWS access keys, call sts:GetCallerIdentity for validation, then probe bedrock:ListFoundationModels and invocation permissions. Validated keys are resold or used for LLM compute theft, generating six-figure Bedrock bills on victim accounts.

IOC Analysis

The pulse set contains three operationally distinct indicator classes:

  • Hostnames/domains (TraderTraitor): delay.servehttp.com, diagnose.hashicorp-terraform.io, hashicorp-terraform.io, arusupport-region1-webhook.online. These are high-confidence blocklist candidates — note the typosquat pattern against terraform.io / HashiCorp branding. DNS sinkholing is effective because developer machines have no legitimate reason to resolve them.
  • IPv4 infrastructure (ARTEX + credential validators): Eight ARTEX C2 IPs and a broader set of AWS-key-validation source IPs (112.78.151.90, 78.109.78.211, 103.160.185.100, etc.). These belong in firewall egress blocks and, critically, in AWS CloudTrail anomaly detection — any GetCallerIdentity or ListFoundationModels call originating from these IPs against your accounts is a confirmed compromised key.
  • File hashes (SHA256/SHA1/MD5): Loader and payload hashes for FLATROOF/ROOFDECK stages (e.g., 188bd4fc…096666, 451b586e…f2da97) and tooling hashes from the Bedrock pulse. Push these to EDR blocklists, but treat hashes as ephemeral — the staged Bash loader means the durable detection is behavioral, not hash-based.

SOC operationalization: ingest the IP/domain sets into your TI platform with 30-day expiry, create CloudTrail alerting on the validator IPs, and pivot the domains through passive DNS (SecurityTrails, VirusTotal, Validin) to identify sibling infrastructure registered on the same dates with similar naming conventions.

Detection Engineering

YAML
---
title: Trojanized Terraform Provider Loader Execution (TraderTraitor FLATROOF/ROOFDECK)
id: 7a1c4f2e-9b3d-4e5a-a1c2-3d4e5f6a7b8c
status: experimental
description: Detects Terraform spawning shell interpreters or downloaders consistent with a trojanized provider pulling a Bash loader, as used by TraderTraitor to deliver FLATROOF/ROOFDECK.
author: Security Arsenal Threat Intelligence
references:
  - https://www.zscaler.com/blogs/security-research/suspected-tradertraitor-group-uses-trojanized-terraform-provider-deliver
date: 2026/10/09
tags:
  - attack.initial_access
  - attack.t1195
  - attack.execution
  - attack.t1059.004
logsource:
  category: process_creation
  product: windows
  definition: Requires Sysmon or equivalent command-line auditing
detection:
  selection_parent:
    ParentImage|endswith:
      - '\terraform.exe'
      - '\terraform-provider'
  selection_child:
    Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\cmd.exe'
      - '\bash.exe'
      - '\curl.exe'
      - '\wget.exe'
      - '\certutil.exe'
  condition: selection_parent and selection_child
falsepositives:
  - Legitimate Terraform provisioners invoking local-exec scripts
level: high
---
title: Network Connection to TraderTraitor HashiCorp Lookalike Infrastructure
id: 8b2d5a3f-ac4e-5f6b-b2d3-4e5f6a7b8c9d
status: experimental
description: Detects DNS or TLS connections to known TraderTraitor FLATROOF/ROOFDECK C2 and loader domains identified in OTX pulse data.
author: Security Arsenal Threat Intelligence
date: 2026/10/09
tags:
  - attack.command_and_control
  - attack.t1071.001
  - attack.t1583.001
logsource:
  category: dns
  product: any
detection:
  selection:
    query|contains:
      - 'hashicorp-terraform.io'
      - 'delay.servehttp.com'
      - 'arusupport-region1-webhook.online'
  condition: selection
falsepositives:
  - Threat research and sandbox detonation
level: critical
---
title: AWS Credential Validation Followed by Bedrock Model Enumeration
id: 9c3e6b4a-bd5f-6a7c-c3e4-5f6a7b8c9d0e
status: experimental
description: Detects the KMON_NOC-style pattern of GetCallerIdentity validation immediately followed by Bedrock ListFoundationModels or model invocation, indicating stolen AWS key testing for LLM access.
author: Security Arsenal Threat Intelligence
references:
  - https://securitylabs.datadoghq.com/articles/beyond-valid-credentials-how-exposed-aws-keys-are-tested-for-amazon-bedrock-access
date: 2026/10/09
tags:
  - attack.discovery
  - attack.t1526
  - attack.t1078.004
logsource:
  product: aws
  service: cloudtrail
detection:
  selection_bedrock:
    eventSource: 'bedrock.amazonaws.com'
    eventName:
      - 'ListFoundationModels'
      - 'InvokeModel'
      - 'Converse'
  filter_known:
    userIdentity.arn|contains:
      - 'bedrock-authorized-role'
  condition: selection_bedrock and not filter_known
falsepositives:
  - Legitimate application Bedrock usage from approved IAM roles
level: high
KQL — Microsoft Sentinel / Defender
// Hunt: TraderTraitor loader domains + ARTEX C2 infrastructure across network and process telemetry
let C2Domains = dynamic(["hashicorp-terraform.io", "diagnose.hashicorp-terraform.io", "delay.servehttp.com", "arusupport-region1-webhook.online"]);
let C2IPs = dynamic(["38.244.50.120", "101.53.80.20", "205.214.59.31", "124.155.252.63", "154.201.79.246", "23.248.249.90", "23.158.220.98", "103.248.148.84"]);
let ValidatorIPs = dynamic(["112.78.151.90", "78.109.78.211", "83.194.172.248", "103.160.185.100", "109.146.93.39", "115.138.247.83"]);
union isfuzzy=true
  (DeviceNetworkEvents
   | where Timestamp > ago(14d)
   | where RemoteUrl has_any (C2Domains) or RemoteIP in (C2IPs) or RemoteIP in (ValidatorIPs)
   | project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteIP, RemoteUrl, ActionType),
  (DeviceProcessEvents
   | where Timestamp > ago(14d)
   | where InitiatingProcessFileName =~ "terraform.exe" or FileName =~ "terraform.exe"
   | where FileName in~ ("powershell.exe", "cmd.exe", "bash.exe", "curl.exe", "wget.exe", "certutil.exe")
   | project Timestamp, DeviceName, InitiatingProcessFileName, FileName, ProcessCommandLine, SHA256)
| order by Timestamp desc
PowerShell
# Security Arsenal - FLATROOF/ROOFDECK & credential-theft artifact hunt
# Run on developer workstations and build agents (elevated)

$ErrorActionPreference = 'SilentlyContinue'
$report = @()

# 1. Known malicious hashes (OTX pulse sample)
$badHashes = @(
  '188bd4fc222c9615540884920caf37ea88bcbea7488e1fb98709e357dd096666',
  '451b586ec9d3c997b319986a1177829653e8ae641c953c05ede6a38616f2da97',
  '923641364ef0ce3a6f1d944890244082b8c7f29c9600c0433b2a0ca9822c0608',
  'c9335bb8a21bd2c568d03b040fb86a0e72145691e54a33495ee0cfaac55835dc'
)
$scanPaths = @("$env:USERPROFILE\Downloads", "$env:TEMP", "$env:APPDATA", "$env:LOCALAPPDATA\Temp")
foreach ($p in $scanPaths) {
  Get-ChildItem -Path $p -Recurse -File -ErrorAction SilentlyContinue | ForEach-Object {
    $h = (Get-FileHash $_.FullName -Algorithm SHA256).Hash.ToLower()
    if ($badHashes -contains $h) {
      $report += [pscustomobject]@{Check='HashMatch'; Path=$_.FullName; Detail=$h}
    }
  }
}

# 2. Terraform provider cache / plugin directory for unsigned or unexpected providers
$tfDirs = @("$env:APPDATA\terraform.d\plugins", "$env:USERPROFILE\.terraform.d", ".terraform\providers")
foreach ($d in $tfDirs) {
  if (Test-Path $d) {
    Get-ChildItem -Path $d -Recurse -File -ErrorAction SilentlyContinue | ForEach-Object {
      $sig = Get-AuthenticodeSignature $_.FullName
      if ($sig.Status -ne 'Valid') {
        $report += [pscustomobject]@{Check='UnsignedTFProvider'; Path=$_.FullName; Detail=$sig.Status}
      }
    }
  }
}

# 3. Persistence artifacts - Run keys, scheduled tasks referencing shell loaders
$runKeys = 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Run','HKLM:\Software\Microsoft\Windows\CurrentVersion\Run'
foreach ($k in $runKeys) {
  Get-ItemProperty $k | ForEach-Object {
    $_.PSObject.Properties | Where-Object { $_.Value -match 'bash|curl|wget|servehttp|hashicorp-terraform' } |
      ForEach-Object { $report += [pscustomobject]@{Check='RunKeyPersistence'; Path=$k; Detail="$($_.Name)=$($_.Value)"} }
  }
}
Get-ScheduledTask | Where-Object { $_.Actions.Execute -match 'powershell|cmd|curl' -and ($_.Actions.Arguments -match 'servehttp|webhook|terraform') } |
  ForEach-Object { $report += [pscustomobject]@{Check='SuspiciousTask'; Path=$_.TaskName; Detail=$_.Actions.Execute} }

# 4. Active or recent connections to pulse IPs
$badIPs = '38.244.50.120','101.53.80.20','205.214.59.31','124.155.252.63','154.201.79.246','23.248.249.90','23.158.220.98','103.248.148.84','112.78.151.90','78.109.78.211','83.194.172.248','103.160.185.100'
Get-NetTCPConnection | Where-Object { $badIPs -contains $_.RemoteAddress } |
  ForEach-Object { $report += [pscustomobject]@{Check='C2Connection'; Path=$_.RemoteAddress; Detail="PID $($_.OwningProcess) State $($_.State)"} }

# 5. AWS CLI credential files modified recently (theft staging indicator)
Get-ChildItem "$env:USERPROFILE\.aws\credentials" | Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-30) } |
  ForEach-Object { $report += [pscustomobject]@{Check='AWSCredRecent'; Path=$_.FullName; Detail=$_.LastWriteTime} }

if ($report) { $report | Format-Table -AutoSize; $report | Export-Csv -NoTypeInformation ".\otx_hunt_$(Get-Date -f yyyyMMdd_HHmm).csv" }
else { Write-Host "No indicators found on $env:COMPUTERNAME" }

Response Priorities

Immediate (0-4h): Block the four TraderTraitor domains and all ARTEX/validator IPs at DNS, proxy, and egress firewall. Push FLATROOF/ROOFDECK hashes to EDR. Query CloudTrail for ListFoundationModels/InvokeModel events sourced from non-corporate IPs in the last 30 days — any hit means a leaked key is live. Inventory developer machines with .terraform directories and audit recently installed providers against the HashiCorp registry.

24 hours: Because FLATROOF/ROOFDECK and the KMON_NOC pipeline both center on credential theft, force rotation of all AWS access keys, SSH keys, and crypto wallet material present on any host that resolved the malicious domains or executed an unverified Terraform provider. Invalidate active AWS sessions, review Bedrock usage and Cost Explorer for anomalous model invocation spend, and require phishing-resistant MFA re-enrollment for affected developer identities.

1 week: Architecturally, pin Terraform providers by checksum and restrict provider installation to a private registry mirror with allow-listed sources. Deploy egress filtering on build agents and developer VLANs so arbitrary outbound HTTPS to uncategorized domains fails closed. Implement IAM guardrails: deny bedrock:* by default, alert on GetCallerIdentity from untrusted ASN ranges, and enable Bedrock invocation logging to a separate security account. Finally, establish an LLM-abuse detection use case in the SOC — ARTEX-class agentic tooling compresses attacker dwell time from days to hours, and detection engineering must assume machine-speed adversaries.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.