Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
North Korean Group Targets Indian IT Firm with MacOS Backdoors

North Korean Group Targets Indian IT Firm with MacOS Backdoors

Posted on September 21, 2026 By CWS

A North Korean cyber group, identified as Jade Sleet, recently infiltrated an Indian IT services company, marking another instance of their targeted attacks on developers. The breach, disclosed by cybersecurity firm SentinelOne, involved macOS backdoors known as FLATROOF and ROOFDECK. These backdoors were previously seen in attacks on the LayerZero bridge of KelpDAO earlier in 2026.

Background on Jade Sleet’s Activities

Jade Sleet, also referred to as PUKCHONG, Slow Pisces, TraderTraitor, and UNC4899, has a notorious history in the Web3 space, often targeting cryptocurrency assets. In 2025, the group was linked to a massive $1.5 billion heist from Bybit’s cold wallet infrastructure, accomplished through a supply chain attack on Safe{Wallet}’s developer setup.

According to Microsoft-owned GitHub, Jade Sleet’s primary targets include entities involved in cryptocurrency and blockchain, as well as vendors servicing these sectors. The group’s tactics often involve social engineering, specifically luring job seekers from compromised firms through fake job interviews.

Technical Details of the Attack

The attackers utilized GitHub repositories themed as infrastructure projects to deceive developers into executing malicious code. Some repositories involved include gtn-candidate-repo, Northwind-IAC, and novacart-interview, which contain a malicious Terraform dependency lock file. By manipulating these files, developers unknowingly download harmful modules during the ‘terraform init’ command execution.

Two distinct malware families, FLATROOF and ROOFDECK, were deployed, targeting ARM-based macOS systems. FLATROOF operates via Telegram for command-and-control, capable of executing commands and stealing data. Meanwhile, ROOFDECK uses the decentralized Nostr protocol for similar purposes, including system reconnaissance and file manipulation.

Implications and Future Outlook

The discovery of these backdoors on a DevOps engineer’s Apple Silicon MacBook in India underlines the persistent risk posed by such sophisticated cyber threats. The malware remained inactive until March 29, when suspicious activities were detected. An updated variant of ROOFDECK was later installed, further complicating detection efforts.

SentinelOne emphasizes the need for heightened vigilance, especially on developer endpoints, which are critical to accessing cloud services and source codes. The reliance on software supply chains for initial access poses a significant cybersecurity challenge, necessitating robust monitoring and defense strategies to protect sensitive development environments from targeted cyber attacks.

The Hacker News Tags:Backdoors, Cryptocurrency, Cybersecurity, DevOps, FLATROOF, Hacking, IT breach, Jade Sleet, macOS, Malware, North Korea, ROOFDECK, SentinelOne, social engineering

Post navigation

Previous Post: Cisco and Android Zero-Day Threats Highlight Cybersecurity Week

Related Posts

Critical Security Patches Released by Ivanti, Fortinet, and SAP Critical Security Patches Released by Ivanti, Fortinet, and SAP The Hacker News
Lazarus Group Deploys Medusa Ransomware in Cyber Attacks Lazarus Group Deploys Medusa Ransomware in Cyber Attacks The Hacker News
Botnet Uses Polygon Blockchain for Resilient Command Control Botnet Uses Polygon Blockchain for Resilient Command Control The Hacker News
New LOTUSLITE Variant Targets Indian Banks and South Korean Policy New LOTUSLITE Variant Targets Indian Banks and South Korean Policy The Hacker News
Badges, Bytes and Blackmail Badges, Bytes and Blackmail The Hacker News
Hackers Exploit Adform Script to Alter Crypto Wallets Hackers Exploit Adform Script to Alter Crypto Wallets The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • North Korean Group Targets Indian IT Firm with MacOS Backdoors
  • Cisco and Android Zero-Day Threats Highlight Cybersecurity Week
  • AI Integration: A Must for Business Success
  • Guarding AI Models Against Sophisticated Ransomware Attacks
  • AI Security Breach: Hugging Face Incident Analysis

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • North Korean Group Targets Indian IT Firm with MacOS Backdoors
  • Cisco and Android Zero-Day Threats Highlight Cybersecurity Week
  • AI Integration: A Must for Business Success
  • Guarding AI Models Against Sophisticated Ransomware Attacks
  • AI Security Breach: Hugging Face Incident Analysis

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark