BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Jade Sleet Hits Indian IT Firm Using macOS Backdoors

North Korean hackers used fake job lures to deploy macOS backdoors via Terraform lock files.

  • North Korean threat actor Jade Sleet compromised an India-based IT services firm using macOS backdoors FLATROOF and ROOFDECK
  • The group deployed weaponized Terraform dependency lock files to deliver malware through fake developer job-interview lures
  • ROOFDECK uses the decentralized Nostr protocol for command-and-control and was updated with evasion tactics after the KelpDAO attack was publicly disclosed

The North Korean hacking group Jade Sleet compromised an India-based IT services provider by targeting a DevOps engineer through social engineering, according to cybersecurity firm SentinelOne.

- Advertisement -

The attackers used macOS backdoors FLATROOF and ROOFDECK, both previously deployed in the KelpDAO LayerZero bridge exploit. Jade Sleet, also known as TraderTraitor and UNC4899, was tied to the $1.5 billion Bybit cold wallet theft in early 2025.

The campaign lured job seekers in DevOps, cryptocurrency, and fintech with fake coding projects. The repositories contained weaponized Terraform dependency lock files that pointed to malicious domains, triggering malware downloads when developers ran the “terraform init” command.

FLATROOF is a Rust-based backdoor that uses Telegram for command-and-control and can steal browser data, terminal histories, and keychain credentials. ROOFDECK relies on the Nostr protocol for decentralized command-and-control and enables file manipulation, remote shell access, and persistence via Launch Agents.

The backdoors were detected on the engineer’s Apple Silicon MacBook as early as March 18, 2026, and remained dormant until March 29. SentinelOne noted that an updated ROOFDECK variant appeared on April 20, one day after LayerZero publicly acknowledged the KelpDAO hack.

- Advertisement -

“This new variant removes symbols and debug information to evade detection,” researchers stated. “Endpoints used for development carry access to cloud, pipelines and source code, making monitoring and protection a high priority.”

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

North Korean hacking group WaterPlum stole $10.7M

North Korean Hacking group WaterPlum stole at least $10.7 million by posing as recruiters...

Coinbase CEO: SEC, CFTC rules more lenient than failed bill

Coinbase CEO Brian Armstrong says the failure of the CLARITY Act may reduce competition...

Visser: AI Agents Are Crypto’s Real Customers, Not Humans

Bitcoin has joined religion and Gold as the only things that survive human and...

Grayscale Zcash ETF Announces 3-for-1 Share Split

Grayscale's ZCash ETF (ZCSH) will execute a 3-for-1 forward share split on Sept. 28,...

REX Launches 2x Leveraged ETF on Bitcoin Treasury Strive

REX Shares and Tuttle Capital Management launched the ASSX ETF on Cboe, offering 2x...

Must Read

12 Hosting Providers To Buy VPS With Bitcoin: An Expert Guide for 2026

You need a VPS. You want to pay with Bitcoin. Simple enough, right?Not quite. The market for crypto VPS = VPS hosting that accepts...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading