{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/actors/jade-sleet/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["Jade Sleet"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["supply-chain","macos","malware","social-engineering","jade-sleet"],"_cs_type":"threat","_cs_vendors":[],"content_html":"\u003cp\u003eJade Sleet, a North Korean threat actor also known as PUKCHONG, Slow Pisces, TraderTraitor, and UNC4899, has been linked to the compromise of an Indian IT services provider. The campaign targets developers in the DevOps and cryptocurrency sectors using sophisticated social engineering lures presented as job interview opportunities. The adversary distributes weaponized GitHub repositories containing malicious Terraform dependency lock files ('.terraform.lock.hcl'). When developers execute 'terraform init', these files force the platform to download and execute attacker-controlled modules from malicious registry domains.\u003c/p\u003e\n\u003cp\u003eFollowing initial access, the attackers deploy two Rust-based macOS implants: FLATROOF (Gaslight), which utilizes Telegram for C2 and browser data theft, and ROOFDECK, which leverages the Nostr protocol for decentralized C2, lateral movement, and persistence via Launch Agents. These tools are designed to target Apple Silicon architectures and implement complex evasion techniques, including the use of updated binaries that strip symbols to circumvent detection.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker establishes contact with a target developer via social engineering lures posing as a job interview opportunity.\u003c/li\u003e\n\u003cli\u003eTarget is directed to a malicious GitHub repository (e.g., 'terraform-candidate-repo') containing a weaponized '.terraform.lock.hcl' file.\u003c/li\u003e\n\u003cli\u003eDeveloper executes 'terraform init' in their local environment, triggering the download of malicious modules from 'registry.hashicorp-aws[.]com'.\u003c/li\u003e\n\u003cli\u003eThe malicious modules execute on the developer's macOS machine, establishing the initial foothold.\u003c/li\u003e\n\u003cli\u003eAttacker deploys FLATROOF for reconnaissance, capturing browser data, keychain credentials, and shell histories.\u003c/li\u003e\n\u003cli\u003eAttacker deploys ROOFDECK to establish persistent C2 via Launch Agents, signed with a private key to verify command integrity.\u003c/li\u003e\n\u003cli\u003eAttacker uses ROOFDECK to perform lateral movement and exfiltrate sensitive cloud, pipeline, and source code credentials.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful compromise allows the actor to gain deep access into corporate DevOps environments, source code pipelines, and cloud infrastructure. Victims are typically individual engineers, but the final objective involves credential exfiltration and unauthorized access to the target organization's sensitive technical assets. Previous activity by this group has resulted in multi-million dollar cryptocurrency thefts and supply chain compromises.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eBlock the domain 'registry.hashicorp-aws[.]com' at the DNS and proxy level.\u003c/li\u003e\n\u003cli\u003eImplement strict monitoring for 'terraform init' commands originating from non-authorized directories or execution contexts.\u003c/li\u003e\n\u003cli\u003eDeploy detection for the creation of unauthorized Launch Agents on macOS endpoints using the Sigma rule provided below.\u003c/li\u003e\n\u003cli\u003eEducate developers on the risks of executing 'terraform init' within untrusted repositories and verify the hash integrity of dependencies.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-21T06:16:05Z","date_published":"2026-09-21T06:16:05Z","id":"https://feed.craftedsignal.io/briefs/2026-09-jade-sleet-backdoors/","summary":"The North Korean threat actor Jade Sleet is conducting supply-chain attacks against DevOps engineers via malicious Terraform configurations that deploy Rust-based macOS backdoors.","title":"Jade Sleet Targets DevOps Engineers with FLATROOF and ROOFDECK Backdoors","url":"https://feed.craftedsignal.io/briefs/2026-09-jade-sleet-backdoors/"}],"language":"en","title":"CraftedSignal Threat Feed - Jade Sleet","version":"https://jsonfeed.org/version/1.1"}