# North Korean Group Jade Sleet Targets Indian IT Firm with Stealthy MacOS Backdoors

*Published September 23, 2026*
*Source: [https://thehackernews.com/2026/09/jade-sleet-linked-to-indian-it-provider.html](https://thehackernews.com/2026/09/jade-sleet-linked-to-indian-it-provider.html)*

## Executive Summary

North Korean hacking group Jade Sleet has compromised an Indian IT services provider using Apple macOS backdoors, highlighting the persistent threat to cryptocurrency and blockchain sectors. The breach demonstrates the critical need for enhanced security measures to protect developer endpoints from sophisticated cyber threats.

## Article

The North Korean hacking group known as Jade Sleet has been identified as the perpetrator behind the breach of a smaller IT services provider based in India. This breach involved sophisticated use of Apple macOS backdoors named FLATROOF and ROOFDECK. SentinelOne, a cybersecurity company, uncovered the details of this breach, highlighting the ongoing threat posed by Jade Sleet, which is also known by other aliases such as PUKCHONG and TraderTraitor. This group has a notorious history, particularly in the Web3 sector, where it has engaged in cryptocurrency theft, including a major heist of $1.5 billion from Bybit in 2025. 

Jade Sleet typically targets individuals and organizations involved with cryptocurrency and blockchain. They also focus on vendors that service these sectors. Their methods often include social engineering tactics, such as fake job interviews, aimed at individuals working in DevOps, cryptocurrency, or financial technology. These deceptive techniques lead victims to execute malicious code. 

The attack on the Indian IT firm involved weaponized Terraform dependencies that redirected developers to malicious domains. These domains facilitated the downloading of attacker-controlled modules, culminating in the installation of Rust-based malware on ARM-based macOS systems. SentinelOne's investigation revealed that the backdoors lay dormant on an Apple Silicon MacBook until they were activated on March 29, 2026. The ROOFDECK malware was later updated on the compromised system, showing the group's effort to evade detection. 

The breach underscores the importance of securing developer endpoints and monitoring for unusual activity. As cyber threats increasingly target software supply chains, protecting these endpoints becomes critical to prevent unauthorized access to cloud infrastructure and source code repositories.
