North Korean Jade Sleet/TraderTraitor Breached Indian IT Provider via Weaponized Terraform Lockfiles, Deploying FLATROOF and ROOFDECK macOS Backdoors
SentinelOne-linked research attributes a March 2026 compromise of an India-based IT services provider to the North Korean cluster Jade Sleet/TraderTraitor, which used fake job-interview GitHub repos with weaponized Terraform lockfiles to install the FLATROOF…
Research from SentinelOne (referred to as SentinelLabs in one report) attributes the compromise of a smaller India-based IT services provider to the North Korean actor tracked as Jade Sleet, also known as TraderTraitor, PUKCHONG, Slow Pisces, and UNC4899; two of the three reports additionally describe it as a DPRK-aligned Lazarus subgroup. The campaign expanded Contagious Interview-style developer targeting beyond cryptocurrency victims by using fake job-interview GitHub repositories containing weaponized .terraform.lock.hcl files that redirected terraform init to typosquatted registries, including registry.hashicorp-aws[.]com and registry.hashicorp-terraform[.]io, to deliver attacker-controlled provider code. The resulting implants, the macOS backdoors FLATROOF (aka Gaslight / macOS.Gaslight) and ROOFDECK, were observed on disk from March 18, 2026, on an Apple Silicon MacBook administered by a DevOps engineer managing AWS, OVH, and OpenStack infrastructure, with activity continuing into June 2026. FLATROOF persisted via a LaunchAgents plist, removed the quarantine attribute to bypass Gatekeeper, collected browser, terminal/command history, and keychain data, and exfiltrated via Telegram command-and-control. ROOFDECK resolved command-and-control through Nostr profiles and relays as a dead-drop mechanism; reports differ on which implant used Launch Agent persistence, with two reports attributing Launch Agents to ROOFDECK and one attributing the LaunchAgents plist to FLATROOF. One report notes the implants activated only during active Cursor sessions to evade detection. The tooling supported theft of API keys used against AWS and Google Cloud, and the same implants were previously tied to the April 2026 KelpDAO–LayerZero incident, in which 116,500 rsETH worth approximately $292M was stolen.
- Attribution by SentinelOne (SentinelLabs in one report) to North Korean cluster Jade Sleet/TraderTraitor, aka PUKCHONG, Slow Pisces, UNC4899; Reports 2 and 3 (GBHackers, Cyber Security News) describe it as a Lazarus subgroup, which Report…
- Victim: India-based IT services provider; implants observed on disk from March 18, 2026, on an Apple Silicon MacBook of a DevOps engineer managing AWS, OVH, and OpenStack infrastructure; activity continued into June 2026.
- Initial access vector: fake job-interview GitHub repositories with weaponized .terraform.lock.hcl files redirecting terraform init to typosquatted registries registry.hashicorp-aws[.]com and registry.hashicorp-terraform[.]io.
- FLATROOF (aka Gaslight, macOS.Gaslight): Telegram C2, steals browser, terminal/command history, and keychain data; per GBHackers it persists via a LaunchAgents plist and bypasses Gatekeeper by removing the quarantine attribute.
- ROOFDECK: resolves C2 through Nostr profiles and relays as a dead-drop mechanism; Reports 1 and 3 say ROOFDECK uses Launch Agents, while Report 2 attributes LaunchAgent persistence to FLATROOF — a discrepancy across sources.
- Evasion: implants activated only during active Cursor sessions and went quiet when the development environment was closed (GBHackers).
- Impact: tooling collected login keychains and supported theft of API keys used against AWS and Google Cloud (Cyber Security News).
- Same implants were tied to the April 2026 KelpDAO–LayerZero incident involving the theft of 116,500 rsETH worth approximately $292M (GBHackers); all three reports link the tooling to the LayerZero/KelpDAO incident.
Coverage timelineoldest first · each row is one article
- · 6d agoJade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
The Hacker News· 76
Jade Sleet breached an Indian IT provider with macOS backdoors FLATROOF and ROOFDECK.
- · 5d agoHackers Weaponize Terraform Lock Files to Infect DevOps Engineers With macOS Backdoors
GBHackers· 80
North Korea-linked TraderTraitor uses weaponized Terraform lock files in fake job-interview GitHub repos to deploy FLATROOF and ROOFDECK macOS backdoors on DevOps engineers.
- · 5d agoNorth Korean TraderTraitor Hackers Use Fake Terraform Job Tests to Deploy macOS Backdoors
Cyber Security News· 78