- North Korean threat actor Jade Sleet compromised an India-based IT services firm using macOS backdoors FLATROOF and ROOFDECK
- The group deployed weaponized Terraform dependency lock files to deliver malware through fake developer job-interview lures
- ROOFDECK uses the decentralized Nostr protocol for command-and-control and was updated with evasion tactics after the KelpDAO attack was publicly disclosed
The North Korean hacking group Jade Sleet compromised an India-based IT services provider by targeting a DevOps engineer through social engineering, according to cybersecurity firm SentinelOne.
The attackers used macOS backdoors FLATROOF and ROOFDECK, both previously deployed in the KelpDAO LayerZero bridge exploit. Jade Sleet, also known as TraderTraitor and UNC4899, was tied to the $1.5 billion Bybit cold wallet theft in early 2025.
The campaign lured job seekers in DevOps, cryptocurrency, and fintech with fake coding projects. The repositories contained weaponized Terraform dependency lock files that pointed to malicious domains, triggering malware downloads when developers ran the “terraform init” command.
FLATROOF is a Rust-based backdoor that uses Telegram for command-and-control and can steal browser data, terminal histories, and keychain credentials. ROOFDECK relies on the Nostr protocol for decentralized command-and-control and enables file manipulation, remote shell access, and persistence via Launch Agents.
The backdoors were detected on the engineer’s Apple Silicon MacBook as early as March 18, 2026, and remained dormant until March 29. SentinelOne noted that an updated ROOFDECK variant appeared on April 20, one day after LayerZero publicly acknowledged the KelpDAO hack.
“This new variant removes symbols and debug information to evade detection,” researchers stated. “Endpoints used for development carry access to cloud, pipelines and source code, making monitoring and protection a high priority.”
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
