North Korean Threat Actor Jade Sleet Compromises Indian IT Provider Using FLATROOF and ROOFDECK Backdoors

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

The North Korean threat actor known as Jade Sleet has been linked to the compromise of a smaller Indian IT services organization, underscoring the group’s ongoing strategy of targeting developers to infiltrate networks. According to reporting by The Hacker News, cybersecurity firm SentinelOne revealed that the attack utilized two Apple macOS backdoors, identified as FLATROOF (also known as Gaslight) and ROOFDECK, which were previously seen in the March-April 2026 attack on KelpDAO’s LayerZero bridge.

Jade Sleet, which is also tracked under various aliases including PUKCHONG and Slow Pisces, has a history of targeting the Web3 sector for cryptocurrency theft. In early 2025, the group was implicated in the theft of approximately $1.5 billion from Bybit’s cold wallet infrastructure due to a supply chain compromise involving Safe{Wallet}’s developer environment.

SentinelOne noted that the campaign employed social engineering tactics, specifically job interview lures, to attract job seekers from the targeted companies. The individuals targeted typically work in DevOps, cryptocurrency, or financial technology sectors. The GitHub repositories used for these lures were designed to mimic infrastructure engineering projects relevant to the companies the attackers were impersonating.

  • gtn-candidate-repo (used in the KelpDAO incident)
  • Northwind-IAC
  • novacart-interview
  • terraform-candidate-repo

The repositories contained a weaponized Terraform dependency lock file that directed the platform to download malicious modules when executed by unsuspecting developers. The attack culminated in the deployment of two Rust-based malware families targeting ARM-based macOS systems:

  • FLATROOF: This backdoor utilizes Telegram for command-and-control (C2) and can execute commands, upload and download files, and steal data from various browsers and system profiles.
  • ROOFDECK: This backdoor employs the Nostr protocol for decentralized C2, enabling system reconnaissance, file manipulation, remote shell access, and persistence through Launch Agents.

SentinelOne’s investigation revealed that the backdoors were detected on a compromised Apple Silicon MacBook belonging to a DevOps engineer as early as March 18, 2026. However, the exact method of delivery remains unclear. The implants remained inactive until March 29, when they began beaconing and executing commands shortly after the engineer opened a specific workspace.

Evidence suggests that ROOFDECK is used as a follow-up tool after establishing an initial foothold on compromised systems. An updated version of ROOFDECK was reportedly deployed on the engineer’s system on April 20, 2026, shortly after LayerZero acknowledged the KelpDAO hack. This new variant aimed to evade detection by removing existing binaries and stripping symbols and debug information.

SentinelOne emphasized that these attacks highlight the importance of securing developer endpoints, which often have access to sensitive cloud environments and source code. The campaign’s focus on third-party vendors and software supply chains indicates a shift in the industry’s exposure, necessitating heightened monitoring and protection measures.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Japan’s Digital Agency Confirms Data Breach Exposing 246,000 Records

In a significant cybersecurity incident, Japan's Digital Agency has confirmed a data breach that exposed approximately 246,000 records. This breach, attributed to a vulnerability...

Canadian Privacy Commissioner Investigates IDScan.net Following Data Breach of 153 Million Driver’s Licenses

Privacy Commissioner of Canada Philippe Dufresne has initiated an investigation into IDScan.net following reports of a significant data breach affecting personal data and scans...

Dubai Government Launches Real-Time Cybersecurity Dashboard in Partnership with Microsoft

The Dubai Electronic Security Center (DESC) has partnered with Microsoft to launch a new Zero Trust assurance dashboard, providing real-time visibility into the cybersecurity...

INS Trishul arrives in Toulon with upgraded BrahMos missile capability

INS Trishul, the Indian Navy’s Talwar-class frigate, arrived at Toulon naval base in France on September 22, 2026, as part of its operational deployment...