Scworld Jade Sleet Targets Indian IT Firm with FLATROOF and ROOFDECK Backdoors
Article Content
- •Jade Sleet linked to breach of Indian IT services firm.
- •Attack utilized FLATROOF and ROOFDECK macOS backdoors.
- •Social engineering tactics involved job interview lures targeting developers.
North Korean threat actor Jade Sleet has been linked to the compromise of a small Indian IT services organization, focusing on developers to infiltrate networks. The attack utilized macOS backdoors known as FLATROOF and ROOFDECK, previously seen in Web3 sector attacks. The campaign involved social engineering tactics, using job interview lures to target individuals in DevOps and cryptocurrency roles. Attackers created fake GitHub repositories with malicious Terraform dependency lock files, leading to the deployment of the backdoors. FLATROOF communicates via Telegram and can exfiltrate browser data, while ROOFDECK uses the Nostr protocol for decentralized command and control. The compromise was detected in March 2026, with an updated ROOFDECK variant deployed later that month. The incident underscores the ongoing threat posed by state-sponsored actors targeting the IT sector.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Jade Sleet, TraderTraitor and Accenture in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
North Korean Fake Worker Scam Targets US Companies North Korean operatives are infiltrating US companies by posing as foreign IT specialists, exploiting trust and business processes to gain legitimate access. These fake workers often secure remote employment under false identities, with reports indicating that they have cost organizations hundreds of millions since…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…