
Jade Sleet Deploys FLATROOF and ROOFDECK Backdoors on Indian IT Provider via Terraform Lock File Lures
Jade Sleet targeted an Indian IT provider's DevOps MacBook with FLATROOF and ROOFDECK backdoors delivered through fake job repositories and malicious Terraform dependencies. The campaign extends prior supply chain operations against crypto firms. Detection on March 18 2026 with activation nine days later highlights dormant implant tactics.
The attack chain began with social engineering lures mimicking job interviews at targeted firms, delivering weaponized GitHub repositories containing malicious .terraform.lock.hcl files that resolved to attacker-controlled domains like registry.hashicorp-aws[.]com. Once executed, the process installed two Rust-based macOS ARM backdoors: FLATROOF using Telegram C2 for file operations and browser data theft including login.keychain-db, and ROOFDECK leveraging Nostr protocol for signed command execution with Launch Agent persistence and reimplemented shell utilities.
Evidence from SentinelOne telemetry shows the implants remained dormant until March 29 before beaconing, matching prior Jade Sleet operations against KelpDAO in March-April 2026 and the 2025 Bybit cold wallet theft estimated at $1.5 billion via Safe{Wallet} supply chain compromise. The Indian victim was identified during broader hunting for these specific backdoors, revealing an unrelated supply chain node used by cryptocurrency and fintech organizations.
This incident underscores North Korean groups' consistent focus on DevOps personnel at vendors serving blockchain targets rather than direct hits on high-value wallets. ROOFDECK's decentralized C2 and command signing differentiate it from typical Lazarus tooling while sharing LightlessCan-style command reimplementation tactics.
Next steps include monitoring for similar terraform-candidate-repo and novacart-interview lures in additional IT services providers, with potential lateral movement from the compromised MacBook into cloud infrastructure.
SentinelOne: ROOFDECK Nostr C2 clusters from India-linked DevOps environments observed in 2+ additional blockchain vendors by September 2026
Sources (2)
- [1]SentinelOne Threat Research Report(https://sentinelone.com/labs/jade-sleet-flatroof-roofdeck)
- [2]Microsoft GitHub Security Advisory(https://github.blog/2023-07-north-korean-threats-web3/)