Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
thehackernews.com Sep 21, 2026

Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

AI-summarised brief · reviewed before publication

SentinelOne revealed that North Korean threat actor Jade Sleet targeted an India‑based IT services firm, deploying Apple macOS backdoors FLATROOF and ROOFDECK. The attack used social‑engineering job‑interview lures to compromise a DevOps engineer’s Apple Silicon MacBook, with the backdoors first detected on March 18, 2026. The implants remained dormant until March 29, then began beaconing, and a newer ROOFDECK variant appeared on April 20, 2026, stripping debug symbols to evade detection. The campaign underscores Jade Sleet’s focus on cryptocurrency and blockchain vendors.

💡 Why It Matters

  • · The breach demonstrates how supply‑chain attacks now hinge on developer endpoints, turning individual engineers into high‑value targets that can unlock entire cloud pipelines.
  • · This shift forces organizations to rethink security beyond perimeter defenses, prioritizing continuous monitoring of development environments.