Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » North Korean-Linked Hackers Target India-Based IT Firm with macOS Backdoors

North Korean-Linked Hackers Target India-Based IT Firm with macOS Backdoors

By:
Last updated:September 21, 2026
Human Written
  • North Korean-linked Jade Sleet compromised an Indian IT services provider using two macOS backdoors tied to the KelpDAO attack.

  • The campaign uses fake coding projects and weaponized Terraform files to target developers and DevOps workers.

  • The malware can reach browser data, credentials, files, cloud access and remote command tools.

North Korean-Linked Hackers Use macOS Backdoors to Target Indian IT Firm

SentinelOne Researchers linked Jade Sleet to an attack on an IT firm in India. The researchers found FLATROOF and ROOFDECK on an Apple Silicon Mac used by a DevOps worker. The same backdoors appeared in the April KelpDAO attack.

The victim had no known ties to crypto. Jade Sleet often goes after crypto and blockchain firms. The group also uses names such as TraderTraitor, UNC4899 and PUKCHONG. SentinelOne tracks TraderTraitor as a DPRK state-sponsored Lazarus subgroup.

Fake Job Projects Hide the Malware

SentinelOne found several GitHub repositories tied to the campaign. They included gtn-candidate-repo, Northwind-IAC, novacart-interview, and terraform-candidate-repo.

The projects look like coding tests for DevOps jobs. That gives the attackers a simple way to reach developers through fake hiring work. The repos contain a bad Terraform lock file called .terraform.lock.hcl. It points Terraform to sites run by the attackers.

Domains such as registry.hashicorp-aws[.]io, registry.hashicorp-aws[.]com and registry.hashicorp-terraform[.]io were discovered. These domains can get a victim into trouble. By executing terraform init, terraform will be able to fetch a malicious provider, and its operation will commence. That can let the attacker run code on the Mac. One developer removed a fake provider after spotting the odd domain.

Attackers use other convincing lures to get Mac users to run malicious code as well. In a separate campaign, a fake CAPTCHA scam delivered new Mac malware targeting crypto wallets, showing how seemingly routine online actions can become the first step in a malware infection.

Backdoors Land on a Developer Mac

SentinelOne found both backdoors on the Mac by March 18, 2026. The team could not prove how they first reached the Mac.

The malware remained quiet until the worker opened a cloudshield project in Cursor on March 29 at 5:00 a.m. UTC. Seconds later, Cursor launched both tools. They then linked to attacker-run servers.

The Mac gave the attackers a useful foothold. The worker used Terraform and Ansible with AWS, OVH and OpenStack. The Mac also held cloud keys and code access.

The risk goes beyond one user. A DevOps Mac can hold keys for cloud tools, code hosts and build jobs. It may also connect to test and live systems. That makes the laptop a useful bridge into a wider network.

SentinelOne also found the worker cloned terraform-candidate-repo on April 13. The next day, FLATROOF re-armed ROOFDECK. That sequence does not prove the repo delivered the malware. SentinelOne said both tools already sat on the Mac by March 18.

FLATROOF Steals Data and Opens the Door

FLATROOF can run shell commands, send files, and stop apps. It also has a Python tool that pulls data from Chrome, Brave, Firefox and Safari. The malware can collect terminal history, installed apps, running processes, and system data. It can also copy the macOS login.keychain-db file.

FLATROOF also gets ROOFDECK ready to run. It removes a macOS block and changes file rights. ROOFDECK can then run without a normal prompt. SentinelOne found FLATROOF under the name SystemUpdate. It uses a path that looks like an Apple system folder.

ROOFDECK Gives Attackers Deeper Control

ROOFDECK gives the attackers more tools. It can check the Mac, manage files, open remote shells and move through a network. The backdoor uses Nostr to find the attack server. It can also use HTTPS to get commands after it finds that server.

ROOFDECK can stay on the Mac through macOS Launch Agents. That lets it start again when the Mac starts. The backdoor also checks signed commands. It uses a public key inside the malware to confirm that the commands came from the operator.

Its tools include file searches, file transfers, process control and system checks. It can also read the Mac clipboard.

Attackers Changed the Malware After Disclosure

On April 20, one day after LayerZero disclosed the KelpDAO attack, the attackers put a new ROOFDECK version on the Mac. The new version removed the old FLATROOF and ROOFDECK files. It also removed symbols and debug data.

The timing may point to an effort to avoid detection. However, SentinelOne said it could only speculate about the reason. The new tool was then called grenight[.]com at times until June 1, SentinelOne said.

LayerZero said attackers stole 116,500 rsETH, worth about $292 million, on April 18. The attack hit KelpDAO’s rsETH bridge, which used LayerZero. LayerZero said the attackers gained control of key systems and used a denial-of-service attack against an outside RPC service.

LayerZero and other firms linked the attack to DPRK actors. CrowdStrike and Mandiant gave medium confidence that UNC4899, TraderTraitor, and Jade Sleet were behind it.

SentinelOne found the same two backdoors in that attack and on the Indian Mac. The India case also shows that Jade Sleet can target firms outside crypto. A developer’s access can open a path to cloud systems, code and other assets.

Developers Remain a Key Target

SentinelOne says the campaign puts developer Macs at the center of the attack path. One laptop can reach cloud accounts, code and build systems. The campaign also shows why fake job tasks need close checks. A coding test can look harmless while hiding a bad dependency.

The case shows one simple risk for firms that rely on remote code work and cloud tools. Attackers may not need to hit a main server first. They may only need one developer to run the wrong project.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.