{"id":3014,"date":"2026-09-21T06:19:10","date_gmt":"2026-09-21T06:19:10","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3014"},"modified":"2026-09-21T06:19:10","modified_gmt":"2026-09-21T06:19:10","slug":"jade-sleet-linked-to-indian-it-provider-breach-with-flatroof-and-roofdeck-backdoors","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3014","title":{"rendered":"Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 21, 2026<\/span><\/span><span class=\"p-tags\">Malware \/ Social Engineering<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi-xFiujwBJLdl6_4wZSMCWdeyCgev2EqszOLkIJ5I9Kbanu6YNmQ36nM615XmLQ-sq2aqldOHfl47jaMNRtDd80RT8k5f6I7eQuszf7wsIg49sEdMW36hsEKUtVUkZabRlGvvDxn7H7COmRCV8qP2pzQm9LNo5QKRnnptxmxTlJ8BMcPxuiqdaMjn-are0\/s1700-nu-rw-lo-l85-e365\/it-services.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>The North Korean threat actor known as <strong>Jade Sleet<\/strong> has been attributed to the compromise of an India-based \u00abmuch smaller organization\u00bb in the information technology (IT) services industry, once again highlighting how the adversary continues to target developers to breach target networks.<\/p>\n<p>Cybersecurity company SentinelOne, which <a href=\"https:\/\/www.sentinelone.com\/labs\/dont-call-us-well-call-your-apis-tradertraitor-backdoors-resurface-on-victim-with-no-crypto-ties\/\" target=\"_blank\">disclosed<\/a> details of the activity, said it involved the use of Apple macOS backdoors tracked as FLATROOF (aka Gaslight) and ROOFDECK, both of which were previously observed in the March-April 2026 attack on <a href=\"https:\/\/www.chainalysis.com\/blog\/kelpdao-bridge-exploit-april-2026\/\" target=\"_blank\">KelpDAO&#8217;s LayerZero bridge<\/a>.<\/p>\n<p>Jade Sleet, also tracked under the monikers PUKCHONG, Slow Pisces, TraderTraitor, and UNC4899, has a history of targeting the Web3 sector for cryptocurrency heists. In early 2025, the hacking group was <a href=\"https:\/\/www.nccgroup.com\/research\/in-depth-technical-analysis-of-the-bybit-hack\/\" target=\"_blank\">tied<\/a> to the theft of about $1.5 billion from Bybit&#8217;s cold wallet infrastructure following a supply chain compromise of Safe{Wallet}&#8217;s developer environment.<\/p>\n<p>\u00abJade Sleet mostly targets users associated with cryptocurrency and other blockchain-related organizations, but also targets vendors used by those firms,\u00bb Microsoft-owned GitHub noted in July 2023.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>SentinelOne said the campaign employs social engineering using job interview lures, a common tactic adopted by multiple North Korean threat actors, to target job seekers from the companies that are breached over the course of the attack. Targeted individuals have been found to work in the DevOps, cryptocurrency, or financial technology space.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>\u00abThe GitHub repository themes for coding project lures are designed as infrastructure engineering projects related to the company that the DPRK actors are posing as,\u00bb security researchers Albert Priego, Alex Delamotte, and Matej Havranek said.<\/p>\n<p>Some of the repositories observed are listed below &#8211;<\/p>\n<ul>\n<li>gtn-candidate-repo (used in the KelpDAO incident)<\/li>\n<li>Northwind-IAC<\/li>\n<li>novacart-interview<\/li>\n<li>terraform-candidate-repo<\/li>\n<\/ul>\n<p>The repositories include a weaponized <a href=\"https:\/\/developer.hashicorp.com\/terraform\/language\/files\/dependency-lock\" target=\"_blank\">Terraform dependency lock file<\/a> (\u00ab.terraform.lock.hcl\u00bb) pointing to malicious domains (e.g., \u00abregistry.hashicorp-aws[.]com\u00bb) that causes the platform to download attacker-controlled modules when the \u00ab<a href=\"https:\/\/developer.hashicorp.com\/terraform\/cli\/commands\/init\" target=\"_blank\">terraform init<\/a>\u00bb command is run by the unsuspecting developer.<\/p>\n<p>The attack chain culminates in the <a href=\"https:\/\/layerzero.network\/publications\/kelpdao-incident-report.pdf\" target=\"_blank\">deployment of two Rust-based malware families<\/a> targeting ARM-based macOS systems &#8211;<\/p>\n<ul>\n<li>FLATROOF, a backdoor that uses Telegram for command-and-control (C2) and is capable of command execution, file upload and download, and data theft via a Python module that can collect Chrome, Brave, Firefox, and Safari browser data, Terminal command histories, installed application listings, system hardware and software profile, a snapshot of running processes, and a copy of <a href=\"https:\/\/attack.mitre.org\/techniques\/T1555\/001\/\" target=\"_blank\">login.keychain-db<\/a><\/li>\n<li>ROOFDECK, a backdoor that uses the <a href=\"https:\/\/redasgard.com\/blog\/hunting-lazarus-part5-eleven-hours-on-his-disk\" target=\"_blank\">Nostr<\/a> protocol for decentralized C2 and is capable of system reconnaissance, file manipulation, remote shell access, lateral movement, and establishing persistence via Launch Agents<\/li>\n<\/ul>\n<p>\u00abROOFDECK commands are signed with the operator&#8217;s private key and their integrity is verified using an embedded public key before execution. The command functionalities are separated into distinct handlers in the source code,\u00bb SentinelOne said.<\/p>\n<p>\u00abThe implant re-implements many common shell commands related to directory and file operations, another tactic often used in more sophisticated North Korea-aligned toolsets, including Lazarus&#8217; LightlessCan.\u00bb<\/p>\n<p>The cybersecurity company said its hunt for the two backdoors uncovered an additional unrelated victim, an IT services provider based in India that was compromised through an Apple Silicon MacBook belonging to a DevOps engineer. The backdoors are said to have been detected on the machine as early as March 18, 2026, although the exact delivery mechanism is unknown at this stage.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-security-guide-b\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiXA4q3EC_2cN4xiJDYmo1tVcCX5KORpjgj8jSp3DntuUZH4f0zu1Ru8jUwzShrquIuOxPb6q9TxJJXGuj7rxDRsXRSD34thOrXdZ9tDITDEj3Ocp0Z6GwhGekRTMhMnFjJ8UA5iSkfSnmnZrFzY5cmUlbCNiTNDNVrZvyef-AR_RLqwITnqZNi6PjeZkPC\/s728-nu-rw-lo-l85-e365\/AI-eBook-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abThey remained dormant until March 29, when beaconing and host activity began,\u00bb the researchers said. \u00abThe implants were first launched by Cursor on March 29, seconds after the cloudshield workspace [~\/DevOps-Automation\/cloudshield] was opened.\u00bb<\/p>\n<p>Evidence indicates that ROOFDECK is deployed as a follow-up tool on compromised hosts following the establishment of initial foothold and control. What&#8217;s more, an updated version of ROOFDECK is said to have been deployed on the DevOps engineer&#8217;s system on April 20, 2026, a day after <a href=\"https:\/\/layerzero.network\/blog\/kelpdao-incident-statement\" target=\"_blank\">LayerZero publicly acknowledged<\/a> the KelpDAO hack.<\/p>\n<p>The new variant, besides removing the existing ROOFDECK and FLATROOF binaries, removes symbols and debug information in an attempt to evade detection.<\/p>\n<p>\u00abThese groups&#8217; initial access efforts include targeting third parties and their software supply chain, which is where much of the industry\u2019s exposure has moved, putting the developer endpoint at the center of the defense,\u00bb SentinelOne said.<\/p>\n<p>\u00abEndpoints used for development carry access to cloud, pipelines and source code, which makes monitoring and protection a high priority for organizations. These campaigns use purpose-built development environments aimed at one engineer at a time, paired with backdoored Terraform builds that differ for each victim.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 21, 2026Malware \/ Social Engineering The North Korean threat actor known as Jade Sleet has been attributed to the compromise of an India-based \u00abmuch smaller organization\u00bb in the&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3015,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[104,278,3474,2237,3472,312,3473,3475,2805],"class_list":["post-3014","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-backdoors","tag-breach","tag-flatroof","tag-indian","tag-jade","tag-linked","tag-provider","tag-roofdeck","tag-sleet"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3014","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3014"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3014\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3015"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3014"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3014"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3014"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}