Protect.Computer
NEWS

North Korea's Jade Sleet Hits Indian IT Firm With New macOS Backdoors

· 1 min read · Malicious byte Network safety
North Korea's Jade Sleet Hits Indian IT Firm With New macOS Backdoors

North Korean hackers tracked as Jade Sleet — also known as PUKCHONG, Slow Pisces, TraderTraitor, and UNC4899 — have breached an unnamed India-based IT services company using a pair of newly documented macOS backdoors. Cybersecurity firm SentinelOne disclosed the attack, which used the same two implants previously deployed in the March–April 2026 compromise of the KelpDAO LayerZero bridge, an incident linked to the $1.5 billion Bybit theft earlier that year.

The attackers gained access through a DevOps engineer’s Apple Silicon MacBook using a social engineering lure: fake GitHub repositories disguised as legitimate infrastructure engineering projects. Hidden inside these repos was a weaponized Terraform dependency lock file (.terraform.lock.hcl) that pointed to attacker-controlled domains — such as registry.hashicorp-aws[.]com — causing Terraform to download malicious modules when the engineer ran terraform init. The backdoors, FLATROOF (also called Gaslight) and ROOFDECK, are written in Rust and target ARM-based macOS systems. They were detected on the compromised machine as early as March 18, 2026, but lay dormant until March 29, when the engineer opened a compromised workspace in the Cursor IDE. ROOFDECK re-implements many common shell commands from scratch — a technique associated with other sophisticated North Korean toolsets — and an updated variant was deployed on April 20, one day after LayerZero publicly acknowledged the KelpDAO breach. That updated version stripped symbols and debug information to hinder analysis.

Sources

Related reading