TechRadar News.
Technology

North Korean APT Jade Sleet Linked to Indian IT Company Breach Involving FLATROOF and ROOFDECK Tools

North Korean APT Jade Sleet Linked to Indian IT Company Breach Involving FLATROOF and ROOFDECK Tools

Cybersecurity researchers have tied the North Korean threat group Jade Sleet to a recent breach of a modest Indian IT services company, illustrating yet another case where the actors leverage software developers to infiltrate larger target networks.

The intrusion came to light when security teams uncovered two malicious pieces, codenamed FLATROOF and ROOFDECK, hidden within the victim’s development environment. Each operates as a backdoor, granting remote command‑and‑control capabilities while staying hard to spot among legitimate code repositories.

The methods employed by Jade Sleet match a wider trend seen with state‑aligned actors of the Democratic People’s Republic of Korea, who frequently breach smaller supply‑chain partners to reach higher‑value downstream targets. By hijacking a developer’s workstation or build system, they can embed malicious code that later spreads into the software delivered to larger enterprises, risking exposure of sensitive information or facilitating espionage.

Intelligence reports label the Indian company as “much smaller” than the multinational customers it serves, and it has not revealed the full extent of the breach. Nonetheless, analysts caution that the detection of FLATROOF and ROOFDECK indicates the attackers aimed for prolonged access, potentially to collect credentials, steal proprietary source code, or move laterally into client networks.

Industry analysts observe that India’s rapidly expanding IT services industry is drawing growing attention from foreign cyber actors. With a vast talent pool of developers and its position as a worldwide outsourcing hub, the nation presents an appealing venue for groups aiming to plant malicious components at the source. The Jade Sleet episode highlights the importance of strong development‑phase security measures, including code‑signing, rigorous access controls, and ongoing monitoring of build pipelines.

Although no public attribution extends beyond the Indian provider, the case reinforces that supply‑chain threats continue to pose a persistent challenge. Regulators and private security firms are likely to issue guidance urging companies to audit their development environments, adopt zero‑trust models, and exchange threat intelligence to curb the risk of comparable breaches moving forward.

Source: feedburner
TechRadar Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related