Skip to content
Jade Sleet Targets Indian IT Firm with FLATROOF and ROOFDECK Backdoors

Jade Sleet Targets Indian IT Firm with FLATROOF and ROOFDECK Backdoors

First seen 22 Sep 2026, 16:29 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 22, 2026 at 17:34 UTC
  • Jade Sleet linked to breach of Indian IT services firm.
  • Attack utilized FLATROOF and ROOFDECK macOS backdoors.
  • Social engineering tactics involved job interview lures targeting developers.

North Korean threat actor Jade Sleet has been linked to the compromise of a small Indian IT services organization, focusing on developers to infiltrate networks. The attack utilized macOS backdoors known as FLATROOF and ROOFDECK, previously seen in Web3 sector attacks. The campaign involved social engineering tactics, using job interview lures to target individuals in DevOps and cryptocurrency roles. Attackers created fake GitHub repositories with malicious Terraform dependency lock files, leading to the deployment of the backdoors. FLATROOF communicates via Telegram and can exfiltrate browser data, while ROOFDECK uses the Nostr protocol for decentralized command and control. The compromise was detected in March 2026, with an updated ROOFDECK variant deployed later that month. The incident underscores the ongoing threat posed by state-sponsored actors targeting the IT sector.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-03-01
Compromise detected in Indian IT firm
An IT services provider's DevOps engineer's MacBook was compromised, leading to the deployment of backdoors.
Scworld
2026-03-15
Updated ROOFDECK variant deployed
A new variant of the ROOFDECK backdoor was deployed, enhancing its capabilities.
Scworld
2026-09-21
Details disclosed by SentinelOne
SentinelOne published findings linking Jade Sleet to the breach and detailing the attack methods used.
The Hacker News

More articles in this cluster (3)

Following this threat?

Track Jade Sleet, TraderTraitor and Accenture in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed