Close Menu
NCIJ Network NCIJ Network
    What's Hot

    All the signs say another financial crisis is coming. Here’s why we need to prepare for it now | Larry Elliott

    September 21, 2026

    Ethiopia conflict: Seven armed groups form alliance against Abiy Ahmed

    September 21, 2026

    England and Wales to have specialist courts for rape cases

    September 21, 2026
    Facebook X (Twitter) Instagram
    Trending
    • All the signs say another financial crisis is coming. Here’s why we need to prepare for it now | Larry Elliott
    • Ethiopia conflict: Seven armed groups form alliance against Abiy Ahmed
    • England and Wales to have specialist courts for rape cases
    • ScrollEd wants to turn textbooks into TikTok
    • Best Voice Cloning APIs in 2026: Speaker Similarity, Consent Checks, and Price per 1M Characters
    • Google Confirms Gemini AI Breached Three Firms
    • ZetaChain Holders Approve L1 Shutdown Plan, Solana Migration
    • Tight Brazil election challenges fragile gains for Amazon conservation
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, September 21
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 21, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 21, 2026Malware / Social Engineering

    The North Korean threat actor known as Jade Sleet has been attributed to the compromise of an India-based “much smaller organization” in the information technology (IT) services industry, once again highlighting how the adversary continues to target developers to breach target networks.

    Cybersecurity company SentinelOne, which disclosed details of the activity, said it involved the use of Apple macOS backdoors tracked as FLATROOF (aka Gaslight) and ROOFDECK, both of which were previously observed in the March-April 2026 attack on KelpDAO’s LayerZero bridge.

    Jade Sleet, also tracked under the monikers PUKCHONG, Slow Pisces, TraderTraitor, and UNC4899, has a history of targeting the Web3 sector for cryptocurrency heists. In early 2025, the hacking group was tied to the theft of about $1.5 billion from Bybit’s cold wallet infrastructure following a supply chain compromise of Safe{Wallet}’s developer environment.

    “Jade Sleet mostly targets users associated with cryptocurrency and other blockchain-related organizations, but also targets vendors used by those firms,” Microsoft-owned GitHub noted in July 2023.

    Cybersecurity

    SentinelOne said the campaign employs social engineering using job interview lures, a common tactic adopted by multiple North Korean threat actors, to target job seekers from the companies that are breached over the course of the attack. Targeted individuals have been found to work in the DevOps, cryptocurrency, or financial technology space.

    “The GitHub repository themes for coding project lures are designed as infrastructure engineering projects related to the company that the DPRK actors are posing as,” security researchers Albert Priego, Alex Delamotte, and Matej Havranek said.

    Some of the repositories observed are listed below –

    • gtn-candidate-repo (used in the KelpDAO incident)
    • Northwind-IAC
    • novacart-interview
    • terraform-candidate-repo

    The repositories include a weaponized Terraform dependency lock file (“.terraform.lock.hcl”) pointing to malicious domains (e.g., “registry.hashicorp-aws[.]com”) that causes the platform to download attacker-controlled modules when the “terraform init” command is run by the unsuspecting developer.

    The attack chain culminates in the deployment of two Rust-based malware families targeting ARM-based macOS systems –

    • FLATROOF, a backdoor that uses Telegram for command-and-control (C2) and is capable of command execution, file upload and download, and data theft via a Python module that can collect Chrome, Brave, Firefox, and Safari browser data, Terminal command histories, installed application listings, system hardware and software profile, a snapshot of running processes, and a copy of login.keychain-db
    • ROOFDECK, a backdoor that uses the Nostr protocol for decentralized C2 and is capable of system reconnaissance, file manipulation, remote shell access, lateral movement, and establishing persistence via Launch Agents

    “ROOFDECK commands are signed with the operator’s private key and their integrity is verified using an embedded public key before execution. The command functionalities are separated into distinct handlers in the source code,” SentinelOne said.

    “The implant re-implements many common shell commands related to directory and file operations, another tactic often used in more sophisticated North Korea-aligned toolsets, including Lazarus’ LightlessCan.”

    The cybersecurity company said its hunt for the two backdoors uncovered an additional unrelated victim, an IT services provider based in India that was compromised through an Apple Silicon MacBook belonging to a DevOps engineer. The backdoors are said to have been detected on the machine as early as March 18, 2026, although the exact delivery mechanism is unknown at this stage.

    Cybersecurity

    “They remained dormant until March 29, when beaconing and host activity began,” the researchers said. “The implants were first launched by Cursor on March 29, seconds after the cloudshield workspace [~/DevOps-Automation/cloudshield] was opened.”

    Evidence indicates that ROOFDECK is deployed as a follow-up tool on compromised hosts following the establishment of initial foothold and control. What’s more, an updated version of ROOFDECK is said to have been deployed on the DevOps engineer’s system on April 20, 2026, a day after LayerZero publicly acknowledged the KelpDAO hack.

    The new variant, besides removing the existing ROOFDECK and FLATROOF binaries, removes symbols and debug information in an attempt to evade detection.

    “These groups’ initial access efforts include targeting third parties and their software supply chain, which is where much of the industry’s exposure has moved, putting the developer endpoint at the center of the defense,” SentinelOne said.

    “Endpoints used for development carry access to cloud, pipelines and source code, which makes monitoring and protection a high priority for organizations. These campaigns use purpose-built development environments aimed at one engineer at a time, paired with backdoored Terraform builds that differ for each victim.”

    Backdoors breach FLATROOF Indian Jade linked provider ROOFDECK Sleet
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Google Confirms Gemini AI Breached Three Firms

    Malicious npm packages evade install-script defenses at runtime

    8 common food additives linked to high blood pressure and heart disease

    Researchers escape OpenAI Codex sandbox to run commands on host

    Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

    Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    All the signs say another financial crisis is coming. Here’s why we need to prepare for it now | Larry Elliott

    September 21, 2026

    Ethiopia conflict: Seven armed groups form alliance against Abiy Ahmed

    September 21, 2026

    England and Wales to have specialist courts for rape cases

    September 21, 2026

    ScrollEd wants to turn textbooks into TikTok

    September 21, 2026
    Latest Posts

    Primary Elections Live Updates: Race Too Close to Call in Democratic Primary for Michigan Senate Seat

    August 5, 2026

    Europe has the defense budget. The test now is delivery. – POLITICO

    August 5, 2026

    As Spain grieves, recurrent heatwaves stir fears of more wildfires | Weather News

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    All the signs say another financial crisis is coming. Here’s why we need to prepare for it now | Larry Elliott

    September 21, 2026

    Ethiopia conflict: Seven armed groups form alliance against Abiy Ahmed

    September 21, 2026

    England and Wales to have specialist courts for rape cases

    September 21, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.