Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors (opens in a new tab)
Why readJade Sleet is now hitting small IT service providers in India with the same macOS backdoors, FLATROOF and ROOFDECK, seen in the KelpDAO LayerZero bridge intrusion.
SentinelOne attributes the compromise of a small India-based IT services firm to North Korea's Jade Sleet (also PUKCHONG, Slow Pisces, TraderTraitor, UNC4899), using the macOS backdoors FLATROOF (aka Gaslight) and ROOFDECK. Both were previously observed in the March-April 2026 attack on KelpDAO's LayerZero bridge, tying the vendor intrusion to the group's crypto-theft operations. The pattern is consistent with earlier work such as the Safe{Wallet} developer-environment compromise that preceded the $1.5bn Bybit theft: developers and vendors as the route into the real target. This is The Hacker News restating SentinelOne's research, so the original writeup carries the indicators.
Indicators1
- Domains
registry[.]hashicorp-aws[.]com