news.mlab.sh
Back to the feed
threat-intel

Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

High
Summary

North Korean threat actor Jade Sleet (also known as PUKCHONG, Slow Pisces, TraderTraitor, and UNC4899) has been linked to a breach of an India-based IT services provider, continuing their targeting of developers and vendors within the cryptocurrency and Web3 sectors. The attack involved deploying backdoors, FLATROOF and ROOFDECK, through social engineering and weaponized Terraform dependencies, ultimately leading to system reconnaissance, file manipulation, and remote shell access. The campaign highlights a trend of targeting third parties and their software supply chains to gain access to developer endpoints.

The North Korean threat actor Jade Sleet has been attributed to the compromise of an India-based "much smaller organization" in the information technology (IT) services industry, once again highlighting how the adversary continues to target developers to breach target networks. Cybersecurity company SentinelOne disclosed details of the activity, which involved the use of Apple macOS backdoors tracked as FLATROOF (aka Gaslight) and ROOFDECK, both of which were previously observed in the March-April 2026 attack on KelpDAO's LayerZero bridge.

Jade Sleet, also tracked under the monikers PUKCHONG, Slow Pisces, TraderTraitor, and UNC4899, has a history of targeting the Web3 sector for cryptocurrency heists. In early 2025, the hacking group was tied to the theft of about $1.5 billion from Bybit's cold wallet infrastructure following a supply chain compromise of Safe{Wallet}'s developer environment. "Jade Sleet mostly targets users associated with cryptocurrency and other blockchain-related organizations, but also targets vendors used by those firms," Microsoft-owned GitHub noted in July 2023.

SentinelOne said the campaign employs social engineering using job interview lures, a common tactic adopted by multiple North Korean threat actors, to target job seekers from the companies that are breached over the course of the attack. Targeted individuals have been found to work in the DevOps, cryptocurrency, or financial technology space. "They remained dormant until March 29, when beaconing and host activity began," the researchers said. "The implants were first launched by Cursor on March 29, seconds after the cloudshield workspace [~/DevOps-Automation/cloudshield] was opened."

Evidence indicates that ROOFDECK is deployed as a follow-up tool on compromised hosts following the establishment of initial foothold and control. What’s more, an updated version of ROOFDECK is said to have been deployed on the DevOps engineer’s system on April 20, 2026, a day after LayerZero publicly acknowledged the KelpDAO hack. The new variant, besides removing the existing ROOFDECK and FLATROOF binaries, removes symbols and debug information in an attempt to evade detection.

The cybersecurity company said its hunt for the two backdoors uncovered an additional unrelated victim, an IT services provider based in India that was compromised through an Apple Silicon MacBook belonging to a DevOps engineer. The backdoors are said to have been detected on the machine as early as March 18, 2026, although the exact delivery mechanism is unknown at this stage.

“They remained dormant until March 29, when beaconing and host activity began,” the researchers said. “The implants were first launched by Cursor on March 29, seconds after the cloudshield workspace [~/DevOps-Automation/cloudshield] was opened.”

FlatROOF is a backdoor that uses Telegram for command-and-control (C2) and is capable of command execution, file upload and download, and data theft via a Python module that can collect Chrome, Brave, Firefox, and Safari browser data, Terminal command histories, installed application listings, system hardware and software profile, a snapshot of running processes, and a copy of login.keychain-db. ROOFDECK, a backdoor that uses the Nostr protocol for decentralized C2 and is capable of system reconnaissance, file manipulation, remote shell access, lateral movement, and establishing persistence via Launch Agents. ROOFDECK commands are signed with the operator’s private key and their integrity is verified using an embedded public key before execution. The command functionalities are separated into distinct handlers in the source code.

“These groups' initial access efforts include targeting third parties and their software supply chain, which is where much of the industry’s exposure has moved, putting the developer endpoint at the center of the defense,” SentinelOne said. “Endpoints used for development carry access to cloud, pipelines and source code, which makes monitoring and protection a high priority for organizations. These campaigns use purpose-built development environments aimed at one engineer at a time, paired with backdoored Terraform builds that differ for each victim.”

Read the full article at The Hacker News