The North Korean threat actor known as Jade Sleet has been linked to the compromise of a smaller Indian IT services organization, underscoring the group’s ongoing strategy of targeting developers to infiltrate networks. According to reporting by The Hacker News, cybersecurity firm SentinelOne revealed that the attack utilized two Apple macOS backdoors, identified as FLATROOF (also known as Gaslight) and ROOFDECK, which were previously seen in the March-April 2026 attack on KelpDAO’s LayerZero bridge.
Jade Sleet, which is also tracked under various aliases including PUKCHONG and Slow Pisces, has a history of targeting the Web3 sector for cryptocurrency theft. In early 2025, the group was implicated in the theft of approximately $1.5 billion from Bybit’s cold wallet infrastructure due to a supply chain compromise involving Safe{Wallet}’s developer environment.
SentinelOne noted that the campaign employed social engineering tactics, specifically job interview lures, to attract job seekers from the targeted companies. The individuals targeted typically work in DevOps, cryptocurrency, or financial technology sectors. The GitHub repositories used for these lures were designed to mimic infrastructure engineering projects relevant to the companies the attackers were impersonating.
- gtn-candidate-repo (used in the KelpDAO incident)
- Northwind-IAC
- novacart-interview
- terraform-candidate-repo
The repositories contained a weaponized Terraform dependency lock file that directed the platform to download malicious modules when executed by unsuspecting developers. The attack culminated in the deployment of two Rust-based malware families targeting ARM-based macOS systems:
- FLATROOF: This backdoor utilizes Telegram for command-and-control (C2) and can execute commands, upload and download files, and steal data from various browsers and system profiles.
- ROOFDECK: This backdoor employs the Nostr protocol for decentralized C2, enabling system reconnaissance, file manipulation, remote shell access, and persistence through Launch Agents.
SentinelOne’s investigation revealed that the backdoors were detected on a compromised Apple Silicon MacBook belonging to a DevOps engineer as early as March 18, 2026. However, the exact method of delivery remains unclear. The implants remained inactive until March 29, when they began beaconing and executing commands shortly after the engineer opened a specific workspace.
Evidence suggests that ROOFDECK is used as a follow-up tool after establishing an initial foothold on compromised systems. An updated version of ROOFDECK was reportedly deployed on the engineer’s system on April 20, 2026, shortly after LayerZero acknowledged the KelpDAO hack. This new variant aimed to evade detection by removing existing binaries and stripping symbols and debug information.
SentinelOne emphasized that these attacks highlight the importance of securing developer endpoints, which often have access to sensitive cloud environments and source code. The campaign’s focus on third-party vendors and software supply chains indicates a shift in the industry’s exposure, necessitating heightened monitoring and protection measures.
Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.


