Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
North Korean threat actor Jade Sleet linked to Indian IT provider breach using macOS backdoors.
Summary
The North Korean threat actor Jade Sleet has been linked to a breach of an Indian IT services company, continuing its pattern of targeting developers. The attack involved the use of macOS backdoors, FLATROOF and ROOFDECK, previously seen in attacks on the Web3 sector. Jade Sleet, also known by other aliases, has a history of cryptocurrency heists and supply chain compromises.
Full text
Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors Ravie LakshmananSep 21, 2026Malware / Social Engineering The North Korean threat actor known as Jade Sleet has been attributed to the compromise of an India-based "much smaller organization" in the information technology (IT) services industry, once again highlighting how the adversary continues to target developers to breach target networks. Cybersecurity company SentinelOne, which disclosed details of the activity, said it involved the use of Apple macOS backdoors tracked as FLATROOF (aka Gaslight) and ROOFDECK, both of which were previously observed in the March-April 2026 attack on KelpDAO's LayerZero bridge. Jade Sleet, also tracked under the monikers PUKCHONG, Slow Pisces, TraderTraitor, and UNC4899, has a history of targeting the Web3 sector for cryptocurrency heists. In early 2025, the hacking group was tied to the theft of about $1.5 billion from Bybit's cold wallet infrastructure following a supply chain compromise of Safe{Wallet}'s developer environment. "Jade Sleet mostly targets users associated with cryptocurrency and other blockchain-related organizations, but also targets vendors used by those firms," Microsoft-owned GitHub noted in July 2023. SentinelOne said the campaign employs social engineering using job interview lures, a common tactic adopted by multiple North Korean threat actors, to target job seekers from the companies that are breached over the course of the attack. Targeted individuals have been found to work in the DevOps, cryptocurrency, or financial technology space. "The GitHub repository themes for coding project lures are designed as infrastructure engineering projects related to the company that the DPRK actors are posing as," security researchers Albert Priego, Alex Delamotte, and Matej Havranek said. Some of the repositories observed are listed below - gtn-candidate-repo (used in the KelpDAO incident) Northwind-IAC novacart-interview terraform-candidate-repo The repositories include a weaponized Terraform dependency lock file (".terraform.lock.hcl") pointing to malicious domains (e.g., "registry.hashicorp-aws[.]com") that causes the platform to download attacker-controlled modules when the "terraform init" command is run by the unsuspecting developer. The attack chain culminates in the deployment of two Rust-based malware families targeting ARM-based macOS systems - FLATROOF, a backdoor that uses Telegram for command-and-control (C2) and is capable of command execution, file upload and download, and data theft via a Python module that can collect Chrome, Brave, Firefox, and Safari browser data, Terminal command histories, installed application listings, system hardware and software profile, a snapshot of running processes, and a copy of login.keychain-db ROOFDECK, a backdoor that uses the Nostr protocol for decentralized C2 and is capable of system reconnaissance, file manipulation, remote shell access, lateral movement, and establishing persistence via Launch Agents "ROOFDECK commands are signed with the operator's private key and their integrity is verified using an embedded public key before execution. The command functionalities are separated into distinct handlers in the source code," SentinelOne said. "The implant re-implements many common shell commands related to directory and file operations, another tactic often used in more sophisticated North Korea-aligned toolsets, including Lazarus' LightlessCan." The cybersecurity company said its hunt for the two backdoors uncovered an additional unrelated victim, an IT services provider based in India that was compromised through an Apple Silicon MacBook belonging to a DevOps engineer. The backdoors are said to have been detected on the machine as early as March 18, 2026, although the exact delivery mechanism is unknown at this stage. "They remained dormant until March 29, when beaconing and host activity began," the researchers said. "The implants were first launched by Cursor on March 29, seconds after the cloudshield workspace [~/DevOps-Automation/cloudshield] was opened." Evidence indicates that ROOFDECK is deployed as a follow-up tool on compromised hosts following the establishment of initial foothold and control. What's more, an updated version of ROOFDECK is said to have been deployed on the DevOps engineer's system on April 20, 2026, a day after LayerZero publicly acknowledged the KelpDAO hack. The new variant, besides removing the existing ROOFDECK and FLATROOF binaries, strips symbols and debug information in an attempt to evade detection. "These groups' initial access efforts include targeting third parties and their software supply chain, which is where much of the industry’s exposure has moved, putting the developer endpoint at the center of the defense," SentinelOne said. "Endpoints used for development carry access to cloud, pipelines and source code, which makes monitoring and protection a high priority for organizations. These campaigns use purpose-built development environments aimed at one engineer at a time, paired with backdoored Terraform builds that differ for each victim." Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE Tweet Share Share Share SHARE MacOS, Malware, Nation-State, Social Engineering, Supply Chain ⚡ Top Stories This Week Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It. How to Evaluate a Unified Security Platform Using a One-Incident Test Stop Trying to Control AI Behavior. Control What AI Can Reach ⭐ Featured Resources Validation Summit ’26: See How Pen Testing, Exposure Validation and BAS Work Together Red Teams: Learn How Attack Path Chaining Changes Automated Security Testing Turn Threat Intelligence Into Verified Risk With Threat-Led Penetration Testing Deploy Browser Security Monitoring in Minutes With a Single Header
Indicators of Compromise
- malware — FLATROOF
- malware — ROOFDECK
- domain — registry.hashicorp-aws[.]com
- mitre_attack — T1059
- mitre_attack — T1071
- mitre_attack — T1105
- mitre_attack — T1041
- mitre_attack — T1047
- mitre_attack — T1547
- mitre_attack — T1560