SentinelOne has attributed the compromise of an India-based IT services organisation — described as a much smaller firm — to the North Korean actor Jade Sleet, tracked elsewhere as PUKCHONG, Slow Pisces, TraderTraitor and UNC4899, using macOS backdoors called FLATROOF (also known as Gaslight) and ROOFDECK that were previously seen in the March–April 2026 attack on KelpDAO's LayerZero bridge. The campaign runs through job-interview lures aimed at job seekers at the targeted company and its vendors, with targeted individuals working in DevOps, cryptocurrency or financial technology; the actor publishes GitHub repositories dressed as infrastructure-engineering projects belonging to the company it is impersonating, among them gtn-candidate-repo, Northwind-IAC, novacart-interview and terraform-candidate-repo. Those repositories contain a weaponised Terraform dependency lock file (.terraform.lock.hcl) pointing at attacker-controlled domains such as registry.hashicorp-aws[.]com, so the malware downloads when an unsuspecting developer runs terraform init. Both payloads are Rust-based and target ARM macOS systems: FLATROOF uses Telegram for command and control and can execute commands, move files and exfiltrate data via a Python module that collects browser data from Chrome, Brave, Firefox and Safari, Terminal histories, installed applications, system profiles, running processes and a copy of login.keychain-db; ROOFDECK uses the Nostr protocol for decentralised command and control, supports remote shells, file manipulation and lateral movement, persists through Launch Agents, and verifies command integrity against an embedded public key before execution. Jade Sleet was previously linked to the roughly US$1.5 billion Bybit cold-wallet theft in early 2025.
| Attribute | Detail |
|---|---|
| Sector | Defence |
| Date | 2026-09-22 |
| Source | The Hacker News |
| Reliability | Tier 2 |