North Korean Threat Actor Jade Sleet Compromises Indian IT Provider Using FLATROOF and ROOFDECK Backdoors

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

The North Korean threat actor known as Jade Sleet has been linked to the compromise of a smaller Indian IT services organization, underscoring the group’s ongoing strategy of targeting developers to infiltrate networks. According to reporting by The Hacker News, cybersecurity firm SentinelOne revealed that the attack utilized two Apple macOS backdoors, identified as FLATROOF (also known as Gaslight) and ROOFDECK, which were previously seen in the March-April 2026 attack on KelpDAO’s LayerZero bridge.

Jade Sleet, which is also tracked under various aliases including PUKCHONG and Slow Pisces, has a history of targeting the Web3 sector for cryptocurrency theft. In early 2025, the group was implicated in the theft of approximately $1.5 billion from Bybit’s cold wallet infrastructure due to a supply chain compromise involving Safe{Wallet}’s developer environment.

SentinelOne noted that the campaign employed social engineering tactics, specifically job interview lures, to attract job seekers from the targeted companies. The individuals targeted typically work in DevOps, cryptocurrency, or financial technology sectors. The GitHub repositories used for these lures were designed to mimic infrastructure engineering projects relevant to the companies the attackers were impersonating.

  • gtn-candidate-repo (used in the KelpDAO incident)
  • Northwind-IAC
  • novacart-interview
  • terraform-candidate-repo

The repositories contained a weaponized Terraform dependency lock file that directed the platform to download malicious modules when executed by unsuspecting developers. The attack culminated in the deployment of two Rust-based malware families targeting ARM-based macOS systems:

  • FLATROOF: This backdoor utilizes Telegram for command-and-control (C2) and can execute commands, upload and download files, and steal data from various browsers and system profiles.
  • ROOFDECK: This backdoor employs the Nostr protocol for decentralized C2, enabling system reconnaissance, file manipulation, remote shell access, and persistence through Launch Agents.

SentinelOne’s investigation revealed that the backdoors were detected on a compromised Apple Silicon MacBook belonging to a DevOps engineer as early as March 18, 2026. However, the exact method of delivery remains unclear. The implants remained inactive until March 29, when they began beaconing and executing commands shortly after the engineer opened a specific workspace.

Evidence suggests that ROOFDECK is used as a follow-up tool after establishing an initial foothold on compromised systems. An updated version of ROOFDECK was reportedly deployed on the engineer’s system on April 20, 2026, shortly after LayerZero acknowledged the KelpDAO hack. This new variant aimed to evade detection by removing existing binaries and stripping symbols and debug information.

SentinelOne emphasized that these attacks highlight the importance of securing developer endpoints, which often have access to sensitive cloud environments and source code. The campaign’s focus on third-party vendors and software supply chains indicates a shift in the industry’s exposure, necessitating heightened monitoring and protection measures.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

EU fines Google €403 million for location data breach, mandates compliance within six months.

DUBLIN: Ireland's Data Protection Commission (DPC), representing the European Union, has imposed a hefty fine of €403 million ($462 million) on Google for violating...

CrowdStrike’s SafeMind Enhances Cyber Defense with Advanced Offensive Techniques

Revolutionizing Cyber Defense: CrowdStrike's SafeMind System In the ever-evolving landscape of cybersecurity, the ability...

Roundcube Security Advisory AV26-503 Warns of Exploited CVE-2026-48842 Vulnerability

Roundcube Security Advisory AV26-503 Warns of Exploited CVE-2026-48842 Vulnerability On May 24, 2026, Roundcube issued a critical security advisory addressing vulnerabilities in its webmail product....