Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2955+ Articles
167+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
NEWS

Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

North Korea's Jade Sleet compromised an Indian IT firm's DevOps engineer via a fake job-interview repo, deploying two new Rust macOS backdoors.

Dylan H.

News Desk

September 21, 2026
3 min read

Fake Job Interview, Real Backdoor

Jade Sleet — the North Korean state-sponsored threat actor also tracked as PUKCHONG, Slow Pisces, TraderTraitor, and UNC4899 — has been linked to the compromise of an India-based IT services company, according to new research. The intrusion began on the workstation of a DevOps engineer running Apple Silicon, and backdoor activity was detectable as early as March 18, 2026, with active command-and-control beaconing starting March 29.

The initial access vector follows Jade Sleet's well-worn playbook: a fake job interview lure aimed at developers. The victim was drawn into a coding exercise built around a project repository styled as terraform-candidate-repo, weaponized with a malicious .terraform.lock.hcl dependency lock file pointing to attacker-controlled domains instead of the legitimate Terraform registry.


Two New Rust Backdoors

The campaign deployed two previously catalogued Rust-based macOS backdoors:

BackdoorC2 ChannelCapabilities
FLATROOF (aka Gaslight)TelegramCommand execution, file theft, browser data and system info harvesting
ROOFDECKNostr protocol (decentralized)Remote shell, file manipulation, persistence via Launch Agents

Using Telegram and the decentralized Nostr protocol for command-and-control lets the operators blend into normal application traffic and sidesteps single-point-of-failure C2 infrastructure that defenders could otherwise sinkhole.

Investigators traced attacker activity into the compromised engineer's own workspace — specifically a ~/DevOps-Automation/cloudshield directory accessed through the Cursor AI code editor — suggesting the intrusion may have pivoted through, or at least touched, developer tooling rather than staying confined to a single terminal session.


Why This Matters

Jade Sleet has spent the past several years refining a single core technique — social-engineering developers, particularly those working in DevOps, cryptocurrency, or fintech roles, with fake recruiting and coding-challenge lures — into a reliable initial-access method for supply chain intrusions. This incident is notable less for novelty and more for reach: it confirms the group continues actively targeting IT services providers in South Asia, expanding well beyond its historically North America- and Europe-heavy target list, and continues investing in macOS-native tooling as Apple Silicon adoption grows among the developer population it targets.

Organizations with DevOps, SRE, or platform engineering staff should treat unsolicited coding-challenge repositories — especially ones bundling Terraform, Docker, or other infrastructure-as-code dependency files — as a credible initial-access vector, not just a phishing nuisance.


Recommendations

  1. Review Terraform and other IaC lock files in any repository provided by an external party before running terraform init or equivalent — verify registry URLs match expected sources
  2. Isolate coding-challenge and interview-exercise environments from production credentials and developer SSH/API keys, ideally in a disposable VM or container
  3. Monitor for anomalous Telegram or unusual outbound protocol traffic (including Nostr relay connections) from developer endpoints
  4. Audit Launch Agent persistence on macOS developer machines for unrecognized entries
  5. Treat AI-assisted code editors (Cursor and similar) as part of the attack surface — review their access logs alongside standard EDR telemetry during incident response

References

  • The Hacker News — Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

Related Reading

  • Transparent Tribe Deploys RustyShade Backdoor via GitHub C2
  • UNC4899 North Korea Crypto Airdrop Trojanized
#North Korea#Jade Sleet#Data Breach#Supply Chain#macOS

Related Articles

Microsoft Links Mastra AI Supply Chain Attack to North Korean Hackers

Microsoft has attributed a 88-minute automated supply chain attack against 142 Mastra AI npm packages — with over 1.1 million combined weekly downloads —...

4 min read

North Korean Hackers Publish 108 Malicious Packages in PolinRider Campaign

Threat actors linked to North Korea's Contagious Interview campaign have published 108 malicious packages and browser extensions across npm, Packagist,...

4 min read

North Korean WaterPlum Hackers Infected 30,000 Devices Worldwide

A joint law enforcement advisory says DPRK-linked WaterPlum hackers compromised 30,000 devices and stole $10.7M in crypto via fake job interviews.

3 min read
Back to all News