North Korean Hackers Target Indian IT Firm with New Mac Backdoors

Jade Sleet compromised an Indian IT provider using FLATROOF and ROOFDECK, exposing a new supply chain risk for developers.
Key points
- Jade Sleet compromised an Indian IT firm using FLATROOF and ROOFDECK malware on an Apple Silicon Mac.
- The attackers used fake job interview repositories to trick a DevOps engineer into running malicious code.
- ROOFDECK uses the Nostr protocol for command and control, making detection and blocking significantly harder.
North Korean cyber actors have compromised a small Indian information technology services provider, according to a report from The Hacker News. The intrusion relied on two sophisticated malware families designed to infect Apple computers, marking a significant expansion of the group's reach beyond the cryptocurrency sector.
The threat actor, known as Jade Sleet, used social engineering tactics to trick a DevOps engineer into installing malicious code. The attack highlights a persistent risk for developers who handle infrastructure tools, as the malware remained hidden on the system for days before becoming active.
Social Engineering Lures Target Developers
The group posed as recruiters, offering job opportunities to IT professionals. They created fake coding projects that appeared legitimate, encouraging candidates to run specific setup commands. These commands triggered the download of malicious software modules from attacker-controlled servers.
This method exploits the trust developers place in standard infrastructure tools. By disguising malicious code as routine project files, the actors bypassed many traditional security checks. The approach is consistent with patterns seen in previous high-profile breaches involving blockchain companies.
Malware Uses Decentralized Communication Channels
The two backdoors, FLATROOF and ROOFDECK, are built in Rust and target ARM-based Mac systems. FLATROOF uses Telegram to send commands to the infected machine, allowing attackers to steal browser data and system information. It also collects sensitive files like login keychains.
ROOFDECK takes a different approach by using the Nostr protocol for communication. This decentralized method makes it harder for defenders to track or block the command-and-control traffic. The software can also move laterally within a network to maintain persistent access.
Detection Delayed Initial Attack Response
The malicious code was present on the victim's machine in mid-March 2026. However, it remained dormant until late March, when it began communicating with external servers. This delay suggests the attackers waited for a specific trigger or timing window to activate the payload.
The exact delivery mechanism for this specific victim remains unclear, but the presence of the backdoors confirms a successful compromise. The incident underscores the need for stricter controls over developer environments and third-party dependencies.






