HomeSecurityJade Sleet: Targeted Indian IT company with FLATROOF & ROOFDECK backdoors

Jade Sleet: Targeted Indian IT company with FLATROOF & ROOFDECK backdoors

Jade Sleet , the notorious North Korean threat linked to billions of dollars in cryptocurrency thefts , has been found responsible for the breach of an Indian IT services company via two sophisticated macOS backdoors codenamed FLATROOF and ROOFDECK . The revelation comes from cybersecurity firm SentinelOne and sheds light on the group’s evolving tactics, which are now targeting smaller IT companies as a stepping stone to larger targets.

Jade Sleet North Korean FLATROOF ROOFDECK group backdoors macOS

Jade Sleet is also known by other names, such as PUKCHONG , Slow Pisces , TraderTraitor , and UNC4899 . The group has a long history of attacks in the Web3 and cryptocurrency sectors, most notably the theft of approximately $1.5 billion from Bybit ’s cold wallet infrastructure in early 2025. This theft is one of the largest in the history of the cryptocurrency industry.

The two backdoors used in the attack were first observed during the attack on KelpDAO's LayerZero bridge in March-April 2026.The discovery that the same tools were used on an Indian IT services company demonstrates that Jade Sleet is expanding its goals beyond the traditional cryptocurrency space, targeting suppliers and partners of the companies it ultimately wants to compromise.

See also: Microsoft: North Korean hackers Moonstone Sleet linked to new ransomware FakePenny

Jade Sleet: The Fake Job Interview Tactic

According to SentinelOne researchers Albert Priego , Alex Delamotte , and Matej Havranek , the campaign uses social engineering through enticing job offers — a classic tactic employed by many North Korean threat groups. The targets are professionals working in the DevOps , crypto , and fintech sectors . Jade Sleet creates fake GitHub repositories that look like real technical infrastructure projects, pretending to represent legitimate companies.

Among the repositories detected are gtn-candidate-repo (used in the KelpDAO) and terraform-candidate-repo. These repositories contain a weaponized Terraform dependency lock (.terraform.lock.hcl), which points to malicious domains such as registry.hashicorp-aws[.]com. When the unsuspecting developer executes the terraform init, the platform automatically downloads modules controlled by the attackers, opening the door for malware.

This technique is particularly dangerous because it exploits tools that DevOps engineers use every day. Terraform is one of the most popular Infrastructure as Code (IaC) , and the trust that developers have in it makes it an ideal attack vector. Jade Sleet exploits this trust to bypass security defenses.

FLATROOF and ROOFDECK: Jade Sleet's weapons for macOS

The attack chain culminates in the installation of two Rust- based backdoors targeting macOS systems with ARM (Apple Silicon) architecture. FLATROOF (also known as Gaslight ) uses Telegram for command-and-control (C2) communication and has extensive capabilities: executing commands, uploading and downloading files, and stealing data via a Python module . This module can collect data from Chrome , Brave , Firefox , and Safari browsers , Terminal command history , a list of installed applications, system hardware and software profiles, a snapshot of running processes, and a copy of login.keychain-db — macOS’s central password repository.

Jade Sleet: Targeted Indian IT company with FLATROOF & ROOFDECK backdoors

ROOFDECK , on ​​the other hand, uses the decentralized Nostr protocol for C2 communication — an innovative option that makes detection and blocking of communication much more difficult. Its capabilities include system reconnaissance, file manipulation, remote shell access , lateral movement within the network, and establishing a permanent presence via Launch Agents . According to SentinelOne, ROOFDECK commands are signed with the operator’s private key and their integrity is verified with an embedded public key before execution, indicating a high level of technical sophistication.

See also: Hackers maliciously use Code Assistant to insert Backdoors

The use of Nostr as a C2 is particularly notable. Nostr is an open, decentralized communication protocol that is not controlled by a central entity, making it nearly impossible to block its traffic without affecting legitimate use. This choice reflects the tendency of sophisticated threat actors to use legitimate, decentralized services to evade detection.

Jade Sleet and the Indian IT company breach

During the investigation into the two backdoors , SentinelOne discovered an additional victim: an Indian IT services company, which was compromised via an Apple Silicon MacBook belonging to a DevOps engineer . The backdoors were detected on the device as early as March 18, 2026 , although the exact delivery mechanism remains unknown. Notably, the implants remained dormant until March 29 , when beaconing and host activity began

According to the researchers, the implants were first launched by Cursor on March 29, seconds after the cloudshield workspace (~/DevOps-Automation/cloudshield) was opened. This detail suggests that Jade Sleet had already infiltrated the engineer's development environment, waiting for the right moment to activate its tools. The fact that the company is described as "much smaller" suggests that Jade Sleet is not exclusively targeting large organizations, but also smaller companies that may be a "bridge" to larger targets.

GitHub had already pointed out in July 2023 that Jade Sleet primarily targets users associated with cryptocurrency and blockchain organizations, as well as the vendors used by these companies. This observation is fully confirmed by the incident with the Indian IT company, which likely serves clients in the cryptocurrency or Web3 space .

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

How to protect yourself from Jade Sleet-type attacks

The Jade Sleet attacks highlight the importance of security in the software supply chain. Organizations — especially those in the DevOps, cryptocurrency, and fintech — must take the risks posed by external repositories and dependencies seriously. Verifying the authenticity of each dependency before executing commands is critical. Also, using detection tools endpoint that can detect suspicious activity on macOS systems is essential.

See also: Sapphire Sleet: North Korea behind the npm debug and chalk attack

Jade Sleet: Targeted Indian IT company with FLATROOF & ROOFDECK backdoors

Tech job seekers should be especially wary of job offers that require code execution or repositories as part of the interview process. Jade Sleet and other North Korean groups routinely exploit this tactic, knowing that prospective employees are often less wary when they believe they are on a skills assessment. Training employees on social engineering and implementing security policies for executing unknown code are key defenses.

Overall, Jade Sleet’s activity highlights that North Korean APT groups continue to evolve their tactics, techniques, and procedures ( TTPs ), adopting new technologies such as the decentralized Nostr protocol and targeting macOS platforms that have traditionally been considered more secure. Cybersecurity in the cryptocurrency and Web3 space remains one of the most critical issues of our time, with billions of dollars at risk from sophisticated state-sponsored groups.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS