Bottom line: North Korean actors successfully used a Terraform lock file to deliver malware to a Mac, exploiting a DevOps engineer.
What's happening: North Korean operators built a foothold on the Mac, which was previously reported vulnerable to a known vulnerability (CVE-2021-4295) with a CVSS score of 7.8. The attack was launched from an IP address in North Korea (151.101.66.153).
What to do: Security teams should monitor Terraform lock files for suspicious activity, and implement additional security controls to prevent similar attacks.