CuraSec

Plan active

Jade Sleet Breaches Indian IT Provider With FLATROOF and ROOFDECK Backdoors

2026-09-21 17:01 UTC · The Hacker News · read the source ↗ #jade-sleet#supply-chain#north-korea
  • Engineer — Learn: Jade Sleet’s continued focus on compromising developers as an entry point into downstream networks is a meaningful supply-chain threat model — no patch or immediate action exists, but review developer endpoint controls and third-party IT vendor access to your environments.
  • SOC/IR — Plan: This active Jade Sleet campaign introduces two named backdoors (FLATROOF and ROOFDECK) worth adding to your threat library; build or tune detections for their behaviors on developer endpoints, particularly macOS, and watch for SentinelOne’s full IOC release to enable a retroactive hunt.
  • Leader — Learn: North Korean actors continuing to use IT services providers as pivot points into downstream targets reinforces supply-chain risk in vendor portfolios; useful context for third-party risk reviews but no immediate leadership action is indicated without evidence of broader systemic impact.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.