Attackers Deploy Go Malware via Malicious Terraform Providers and HashiCorp Registry
Cybersecurity researchers have identified a new method of malware distribution involving malicious Go Modules and Terraform providers, utilizing the centralized HashiCorp registry. This marks the first instance of threat actors leveraging this repository for malicious payloads. The malware, which shares characteristics with the Graphalgo campaign previously linked to North Korean threat actors, is delivered through various packages including `indexed-btree`, `mathsbase`, and `graphcore-js`. The attack often begins with fake job interviews on platforms like LinkedIn and Facebook, where prospective developers are asked to complete coding tasks that introduce malicious dependencies. The malware collects system information, including hardware attributes and operating system details, and transmits it to attacker-controlled Slack channels. The payload is encrypted and its full functionality remains unknown due to asymmetric cryptography. This sophisticated operation uses dual command-and-control (C2) channels, e...