Back to Intelligence

TraderTraitor Terraform Supply-Chain Campaign, Blockchain-C2 Hotel Intrusion Wave & Flax Typhoon Disruption: OTX Pulse Analysis — Enterprise Detection Pack

SA
Security Arsenal Team
October 9, 2026
10 min read

Three concurrent OTX pulses paint a picture of an accelerating convergence between supply-chain compromise, novel C2 evasion, and state-sponsored infrastructure abuse.

Pulse 1 — TraderTraitor (DPRK-nexus): Zscaler ThreatLabz uncovered a campaign weaponizing the developer toolchain itself. A trojanized Terraform provider, hosted behind the HashiCorp lookalike domain hashicorp-terraform.io (with diagnose.hashicorp-terraform.io as a support endpoint), downloads a Bash loader from delay.servehttp.com. The loader fingerprints the victim OS and deploys platform-appropriate payloads from the FLATROOF and ROOFDECK families. Targeting is precise: cryptocurrency and Web3 developers — the exact population whose workstations hold wallet keys, signing credentials, and cloud deployment tokens. This follows TraderTraitor's established tradecraft of trojanizing trusted software to reach high-value crypto-theft objectives.

Pulse 2 — Blockchain-C2 Hospitality Campaign: Cofense documents phishing emails impersonating guest complaints, reviews, and inquiries aimed at hotel and accommodation staff. Malicious LNK files disguised as images kick off chains deploying EtherRAT, TONResolver, PureRAT, and NetSupport Manager RAT. The defining characteristic: C2 resolution via public blockchain APIs (Ethereum and TON). By encoding C2 addresses in blockchain transactions and querying legitimate public API endpoints, the actors make traditional domain blocking and DNS sinkholing nearly useless — the 'infrastructure' is immutable, distributed, and indistinguishable from legitimate Web3 traffic.

Pulse 3 — Flax Typhoon (PRC-nexus) Disruption: The FBI seized seven domains tied to Integrity Technology Group, a Chinese firm allegedly supplying offensive tooling to Beijing-backed operators. Flax Typhoon's Mirai-derived botnet has been compromising internet-connected devices since 2021 for network scanning and lateral movement, hitting a South Carolina power company, Taiwanese universities, and targets across the US, Japan, Poland, and Taiwan. A joint advisory from seven governments confirms systematic theft of sensitive data from energy, government, NGO, transportation, and education sectors.

Collective assessment: All three campaigns share a strategic pattern — abusing trusted infrastructure (developer tooling, public blockchains, IoT botnets) rather than building noisy bespoke infrastructure. Detection must shift from reputation-based blocking to behavioral analytics.

Threat Actor / Malware Profile

TraderTraitor (Lazarus Group sub-cluster, DPRK)

  • Distribution: Trojanized Terraform provider delivered to crypto/Web3 developers; likely via social engineering on developer channels, poisoned package registries, or malicious pull requests.
  • Payload behavior: OS-aware Bash loader selecting FLATROOF/ROOFDECK variants per platform (cross-platform coverage of macOS/Linux developer workstations).
  • C2: HashiCorp-themed typosquats (hashicorp-terraform.io, diagnose.hashicorp-terraform.io), dynamic DNS (delay.servehttp.com), webhook-style endpoints (arusupport-region1-webhook.online), and Nostr-protocol references per tagging — decentralized relay abuse consistent with Lazarus experimentation.
  • Objective: Cryptocurrency theft via key/credential harvesting from developer environments.

EtherRAT / TONResolver / PureRAT / NetSupport Manager

  • Distribution: Spear-phishing hospitality staff with fake guest complaints/reviews; LNK files masquerading as images.
  • Payload behavior: LNK → script chain → RAT staging; NetSupport Manager abused as a legitimate-signed remote access payload.
  • C2: Dead-drop resolver technique — malware queries public Ethereum/TON blockchain APIs to decode operator-controlled wallet transaction data into live C2 addresses. Secondary infrastructure uses fast-flux throwaway domains (gateway001kir.com, zloapobikahy23.bond, etc.) and Cloudflare Tunnel hosts (*.trycloudflare.com).
  • Anti-analysis: Blockchain indirection defeats sandbox network detonation reputation scoring; Cloudflare Tunnels evade perimeter allowlists.

Flax Typhoon (PRC state-sponsored)

  • Distribution: Exploitation of edge/IoT devices using legacy CVEs (CVE-2015-5477, CVE-2016-3081, CVE-2015-3306, CVE-2021-3199) to build a Mirai-based botnet; FishHub tooling for post-compromise operations.
  • Behavior: Botnet nodes perform vulnerability scanning (microscan tag) and act as relay/proxy layers to mask operator origin.
  • Objective: Long-dwell espionage against critical infrastructure and government/academic targets.

IOC Analysis

The indicator set breaks into four operational classes:

  1. Domains/hostnames (highest value, lowest TTL): Typosquat and DGA-style domains — hashicorp-terraform.io, diagnose.hashicorp-terraform.io, arusupport-region1-webhook.online, gateway001kir.com, sslgateway001.com, zloapobikahy23.bond, kadmecnp-643laolmd.com, lermontov-656idlop.com, 98aicai.com, youtubecard.com, c0cc.cc, 98aicode.com. Push to DNS sinkhole/proxy block lists immediately; add retroactive DNS log searches for 90 days.
  2. Dynamic infrastructure: delay.servehttp.com (ServeHTTP dynamic DNS) and lotus-vista-additions-joshua.trycloudflare.com (Cloudflare Tunnel). Alert on the pattern — long random subdomain labels under trycloudflare.com — not just the exact FQDN.
  3. File hashes: SHA256/SHA1/MD5 for FLATROOF/ROOFDECK loader and payload samples. Import into EDR block lists; low long-term value due to recompilation, but essential for retrospective scoping.
  4. CVEs (Pulse 3): Not network IOCs — these are patch-priority signals. Audit internet-facing devices for CVE-2015-5477 (BIND), CVE-2015-3306 (ProFTPD), CVE-2016-3081, CVE-2021-3199 exposure. Any unpainted legacy BIND/ProFTPD service on the perimeter is a botnet recruitment candidate.

Tooling: Decode blockchain-C2 behavior with Zeek/Suricata full-pcap at egress (flag HTTPS to api.toncenter.com, api.etherscan.io, tonapi.io from non-browser processes). Operationalize hashes via MISP → EDR sync; domains via DNS firewall (RPZ). Use dnstwist-style monitoring to catch new HashiCorp/vendor typosquats proactively.

Detection Engineering

YAML
---
title: Trojanized Terraform Provider Loader Execution (TraderTraitor / FLATROOF / ROOFDECK)
id: 7f3a2c1e-9b4d-4e6a-a2f1-tt2026a001
status: experimental
description: Detects Bash loader execution chains spawned from Terraform provider processes or downloads from HashiCorp lookalike infrastructure, consistent with TraderTraitor trojanized provider tradecraft.
author: Security Arsenal Threat Intelligence
date: 2026/10/09
references:
  - https://www.zscaler.com/blogs/security-research/suspected-tradertraitor-group-uses-trojanized-terraform-provider-deliver
logsource:
  category: process_creation
  product: linux
  product: macos
detection:
  selection_parent:
    ParentImage|endswith:
      - '/terraform'
      - '/terraform-provider'
  selection_child:
    Image|endswith:
      - '/bash'
      - '/sh'
      - '/curl'
      - '/wget'
      - '/python'
      - '/python3'
      - '/osascript'
  selection_network_ref:
    CommandLine|contains:
      - 'hashicorp-terraform.io'
      - 'delay.servehttp.com'
      - 'arusupport-region1-webhook.online'
  condition: (selection_parent and selection_child) or selection_network_ref
falsepositives:
  - Legitimate Terraform provider plugins invoking helper binaries (rare; providers are Go binaries and do not normally spawn shells)
level: high
tags:
  - attack.initial_access
  - attack.t1195.002
  - attack.execution
  - attack.t1059.004
---
title: Blockchain API Query for C2 Resolution (EtherRAT / TONResolver)
id: 7f3a2c1e-9b4d-4e6a-a2f1-bc2026a002
status: experimental
description: Detects non-browser processes making HTTPS connections to public blockchain API endpoints used by EtherRAT and TONResolver to resolve C2 infrastructure from on-chain data.
author: Security Arsenal Threat Intelligence
date: 2026/10/09
references:
  - https://cofense.com/blog/from-guest-complaints-to-malware-blockchain-abuse-targets-hotels
logsource:
  category: network_connection
  product: windows
detection:
  selection_dest:
    DestinationHostname|contains:
      - 'api.etherscan.io'
      - 'api.toncenter.com'
      - 'tonapi.io'
      - 'api.bscscan.com'
      - 'polygonscan.com'
  filter_browsers:
    Image|endswith:
      - '\chrome.exe'
      - '\msedge.exe'
      - '\firefox.exe'
      - '\brave.exe'
  filter_wallets:
    Image|contains:
      - '\MetaMask\'
      - '\Ledger\'
      - '\Trezor\'
  condition: selection_dest and not 1 of filter_*
falsepositives:
  - Crypto portfolio tracker desktop applications
  - Internal Web3 development tooling (scope by OU/user group for hospitality environments)
level: high
tags:
  - attack.command_and_control
  - attack.t1071.001
  - attack.t1102
---
title: Malicious LNK Execution via Guest-Complaint Phishing (Hospitality Campaign)
id: 7f3a2c1e-9b4d-4e6a-a2f1-lnk2026a003
status: experimental
description: Detects LNK shortcut files spawning script interpreters or LOLBins, matching the fake guest-complaint phishing chain delivering EtherRAT, TONResolver, PureRAT, and NetSupport Manager RAT.
author: Security Arsenal Threat Intelligence
date: 2026/10/09
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
      - '\explorer.exe'
  selection_cmd:
    CommandLine|contains:
      - '.lnk'
  selection_child:
    Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\wscript.exe'
      - '\cscript.exe'
      - '\mshta.exe'
      - '\rundll32.exe'
      - '\msiexec.exe'
  condition: selection_parent and selection_cmd and selection_child
falsepositives:
  - Administrative shortcut automation; baseline and whitelist known admin LNK paths
level: medium
tags:
  - attack.execution
  - attack.t1204.002
  - attack.defense_evasion
  - attack.t1218
KQL — Microsoft Sentinel / Defender
// Blockchain-C2 & TraderTraitor infrastructure hunt — Microsoft Sentinel
// Covers: blockchain API C2 resolution, HashiCorp typosquat contact, hotel-campaign domains, Cloudflare Tunnel abuse
let BlockchainAPIs = dynamic(["api.etherscan.io","api.toncenter.com","tonapi.io","api.bscscan.com","polygonscan.com","api.trongrid.io"]);
let PulseIOCs = dynamic(["hashicorp-terraform.io","diagnose.hashicorp-terraform.io","delay.servehttp.com","arusupport-region1-webhook.online","gateway001kir.com","sslgateway001.com","waygatterol002.com","zloapobikahy23.bond","perrine90-deltajohnsons.com","kadmecnp-643laolmd.com","lermontov-656idlop.com","98aicai.com","youtubecard.com","c0cc.cc","98aicode.com"]);
let BrowserProc = dynamic(["chrome.exe","msedge.exe","firefox.exe","brave.exe","iexplore.exe"]);
let NetHits =
    DeviceNetworkEvents
    | where TimeGenerated > ago(14d)
    | where RemoteUrl has_any (PulseIOCs)
       or (RemoteUrl has_any (BlockchainAPIs) and not(InitiatingProcessFileName has_any (BrowserProc)))
       or (RemoteUrl has "trycloudflare.com" and not(InitiatingProcessFileName has_any (BrowserProc)))
    | project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, ActionType, HuntType="NetworkIOC";
let ProcHits =
    DeviceProcessEvents
    | where TimeGenerated > ago(14d)
    | where ProcessCommandLine has_any (PulseIOCs)
       or (InitiatingProcessFileName =~ "explorer.exe" and ProcessCommandLine has ".lnk" and FileName in~ ("powershell.exe","wscript.exe","mshta.exe","rundll32.exe"))
    | project TimeGenerated, DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName, SHA256, HuntType="ProcessBehavior";
union NetHits, ProcHits
| sort by TimeGenerated desc
PowerShell
# Security Arsenal — OTX Pulse IOC Hunt (2026-10-09)
# Targets: TraderTraitor FLATROOF/ROOFDECK artifacts, EtherRAT/TONResolver/PureRAT/NetSupport persistence, Flax Typhoon relay signs
# Run elevated on endpoints; export results for central collection.

$Report = [System.Collections.Generic.List[object]]::new()

# --- 1. File hash sweep (FLATROOF / ROOFDECK samples) ---
$HashIOCs = @(
  "188bd4fc222c9615540884920caf37ea88bcbea7488e1fb98709e357dd096666",
  "451b586ec9d3c997b319986a1177829653e8ae641c953c05ede6a38616f2da97",
  "9d78ece09457907b730d139e4e0c64dd",
  "8473f85bda00dfa3ecd2385dd38f69600d1d64a6"
)
$SearchPaths = @("$env:TEMP","$env:APPDATA","$env:LOCALAPPDATA","$env:USERPROFILE\Downloads","$env:USERPROFILE\.terraform.d","C:\ProgramData")
foreach ($p in $SearchPaths) {
  if (Test-Path $p) {
    Get-ChildItem -Path $p -Recurse -File -ErrorAction SilentlyContinue | ForEach-Object {
      try {
        $h = Get-FileHash -Path $_.FullName -Algorithm SHA256 -ErrorAction Stop
        $hm = (Get-FileHash -Path $_.FullName -Algorithm MD5 -ErrorAction SilentlyContinue).Hash
        if ($HashIOCs -contains $h.Hash.ToLower() -or $HashIOCs -contains $hm.ToLower()) {
          $Report.Add([pscustomobject]@{Type="HashMatch"; Path=$_.FullName; SHA256=$h.Hash})
        }
      } catch {}
    }
  }
}

# --- 2. DNS cache check for pulse domains ---
$DomainIOCs = "hashicorp-terraform.io|delay.servehttp.com|arusupport-region1-webhook.online|gateway001kir.com|sslgateway001.com|waygatterol002.com|zloapobikahy23.bond|perrine90-deltajohnsons.com|trycloudflare.com|kadmecnp-643laolmd.com|lermontov-656idlop.com|98aicai.com|youtubecard.com|c0cc.cc|98aicode.com"
Get-DnsClientCache -ErrorAction SilentlyContinue | Where-Object { $_.Entry -match $DomainIOCs } | ForEach-Object {
  $Report.Add([pscustomobject]@{Type="DNSCacheHit"; Path=$_.Entry; SHA256=""})
}

# --- 3. Persistence: Run keys, scheduled tasks referencing script interpreters or blockchain API hosts ---
$RunKeys = @("HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run","HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run","HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce")
foreach ($k in $RunKeys) {
  if (Test-Path $k) {
    (Get-ItemProperty $k).PSObject.Properties | Where-Object { $_.Value -match "powershell|wscript|mshta|rundll32|\.lnk|etherscan|toncenter|tonapi" } | ForEach-Object {
      $Report.Add([pscustomobject]@{Type="RunKey"; Path="$k\$($_.Name)"; SHA256=$_.Value})
    }
  }
}
Get-ScheduledTask -ErrorAction SilentlyContinue | Where-Object { ($_.Actions.Execute -match "powershell|wscript|mshta") -or ($_.Actions.Arguments -match "etherscan|toncenter|tonapi|cloudflare") } | ForEach-Object {
  $Report.Add([pscustomobject]@{Type="ScheduledTask"; Path=$_.TaskName; SHA256=($_.Actions.Execute + " " + $_.Actions.Arguments)})
}

# --- 4. Live network connections to pulse infrastructure / blockchain APIs from odd processes ---
Get-NetTCPConnection -State Established -ErrorAction SilentlyContinue | ForEach-Object {
  $proc = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
  try {
    $resolved = [System.Net.Dns]::GetHostEntry($_.RemoteAddress).HostName
    if ($resolved -match $DomainIOCs -or $resolved -match "etherscan|toncenter|tonapi") {
      $Report.Add([pscustomobject]@{Type="NetConnection"; Path="$($proc.ProcessName) ($($proc.Id)) -> $($_.RemoteAddress):$($_.RemotePort) [$resolved]"; SHA256=""})
    }
  } catch {}
}

$Report | Format-Table -AutoSize
$Report | Export-Csv -Path "$env:TEMP\otx_pulse_hunt_20261009.csv" -NoTypeInformation
Write-Host "[+] Hunt complete. $($Report.Count) findings exported to $env:TEMP\otx_pulse_hunt_20261009.csv"

Response Priorities

Immediate (0–4 hours)

  • Push all domains/hostnames from both criminal and APT pulses to DNS RPZ, SWG, and EDR network block lists; sinkhole where possible for victim telemetry.
  • Import the four file hashes into EDR prevention (not just detection) mode.
  • Block or alert on outbound HTTPS from non-browser processes to public blockchain API endpoints (etherscan, toncenter, tonapi, trongrid) — this is the single highest-signal behavioral chokepoint for the EtherRAT/TONResolver family.
  • Audit any Terraform/OpenTofu usage: enumerate installed providers, verify checksums against the official HashiCorp registry, and alert on providers sourced from non-standard registries.
  • Hunt retroactively (90 days) in DNS/proxy logs for all listed IOCs plus wildcard *.trycloudflare.com usage outside approved dev tunnels.

24 Hours

  • Credential exposure scoping: TraderTraitor targets developers specifically for wallet keys, cloud IAM tokens, and signing keys. Any host matching a FLATROOF/ROOFDECK artifact requires immediate rotation of: SSH keys, cloud provider tokens, CI/CD secrets, hardware-wallet-adjacent seed material, and registry publish credentials. Treat developer workstations as Tier-0 assets in this scenario.
  • Hospitality-facing organizations: force password resets for any user who opened a 'guest complaint' attachment in the last 30 days; enable MFA enforcement gaps check on front-desk/reservations mailboxes.
  • Review email gateway detonation verdicts for LNK-in-archive attachments and tighten LNK handling policy (strip or convert LNK attachments at the gateway).
  • Perimeter audit against the four Flax Typhoon CVEs — legacy BIND, ProFTPD, and unpatched IoT/edge devices are botnet recruitment surfaces; isolate or patch.

1 Week

  • Architecture hardening — developer toolchain: Pin Terraform providers by checksum in a private registry mirror; enforce terraform init through artifact-proxy only; deploy egress policy blocking direct internet fetches from build/dev hosts.
  • Egress re-architecture for blockchain C2: Deploy TLS inspection or process-aware egress filtering so blockchain API calls can be attributed to a process, not just a host; alert on any host without an approved Web3 business function contacting these APIs.
  • Sector-specific controls (hospitality): Implement attachment sandboxing tuned for LNK/ISO/IMG chains, deploy Attack Surface Reduction rules blocking Office/Explorer child processes spawning script interpreters, and segment front-desk systems from PMS/POS networks.
  • Edge device hygiene: Inventory internet-facing IoT/network appliances, disable telnet/legacy management interfaces, and subscribe to CISA/joint-advisory feeds on Flax Typhoon infrastructure rotations — FBI domain seizures displace but do not eliminate the botnet.
  • Feed all IOCs into your TI platform with expiry dates (domains: 90d, hashes: 1y, CVEs: permanent watch) and schedule re-validation.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.