Don't Call Us, We'll Call Your APIs

Don't Call Us, We'll Call Your APIs

North Korean actors successfully used a Terraform lock file to deliver malware to a Mac, exploiting a DevOps engineer.

Bottom line: North Korean actors successfully used a Terraform lock file to deliver malware to a Mac, exploiting a DevOps engineer.

What's happening: North Korean operators built a foothold on the Mac, which was previously reported vulnerable to a known vulnerability (CVE-2021-4295) with a CVSS score of 7.8. The attack was launched from an IP address in North Korea (151.101.66.153).

What to do: Security teams should monitor Terraform lock files for suspicious activity, and implement additional security controls to prevent similar attacks.

Source: SentinelLabs