Jade Sleet Compromises Indian IT Firm via DevOps Lure
🛡️ SentinelOne attributes a campaign by the North Korean-linked group Jade Sleet to the compromise of an India-based IT services provider, using macOS backdoors FLATROOF and ROOFDECK. The attackers employed job-interview and coding project lures with weaponized Terraform lock files to trick developers into fetching malicious modules. FLATROOF uses Telegram for C2 and data theft, while ROOFDECK leverages the Nostr protocol for decentralized C2 and persistent, signed command execution. The incident underscores the growing risk to developer endpoints and supply chain vectors.
