North Korean threat actor Jade Sleet has compromised an India-based IT services provider, deploying previously undisclosed backdoors called FLATROOF and ROOFDECK to maintain persistent access to victim networks. Security firm SentinelOne disclosed the intrusion, which underscores Jade Sleet's sustained targeting of software developers and IT service providers as initial entry points into larger enterprise environments.

Jade Sleet, also tracked as Ruby Sleet by some security researchers, represents North Korea's ongoing effort to infiltrate supply chains through smaller, less-defended organizations. By breaching an IT services firm, the adversary gains access to that provider's customer base and internal development infrastructure. This attack pattern reflects a deliberate strategy to compromise downstream targets through trusted service relationships.

SentinelOne's investigation revealed that the attackers deployed FLATROOF and ROOFDECK backdoors following initial compromise. These tools enable remote command execution and persistent access, allowing attackers to maintain control over compromised systems even after detected intrusion attempts. The use of previously unreported backdoors demonstrates North Korean operators' continued investment in custom malware development and operational security.

The targeting of Indian IT providers carries particular significance. India hosts some of the world's largest software outsourcing and IT consulting firms. These organizations manage critical infrastructure, financial systems, and enterprise applications for clients across multiple sectors and geographies. A compromise at this level threatens downstream customers globally, not just the immediately affected firm.

Jade Sleet's operational pattern matches documented North Korean APT behavior. The group historically targets organizations across defense, finance, healthcare, and government sectors. Previous campaigns attributed to Jade Sleet involved spear phishing, watering hole attacks, and exploitation of unpatched software vulnerabilities to establish initial access. The group then deploys custom tools designed to evade detection by security monitoring solutions.

The use of Apple platforms in this campaign requires particular attention. Historically, macOS and iOS malware receive less security scrutiny than Windows-focused threats. Attackers exploit this disparity to maintain presence on systems administrators often assume less vulnerable. SentinelOne's reference to Apple involvement suggests the compromised IT provider may have used Mac-based development environments or that attackers attempted to establish cross-platform persistence.

Organizations relying on Indian IT service providers face immediate risk from this disclosure. Customers should assume potential exposure to compromised build environments, supply chain tools, and internal systems. This means binaries, libraries, and software updates distributed by affected providers could carry embedded backdoors or malicious code.

Detection and response actions include hunting for FLATROOF and ROOFDECK backdoors within internal networks, reviewing access logs from the compromised IT provider's systems, and auditing recent software updates or patches received from Indian service providers. Security teams should enable behavioral detection rules for these backdoors and implement network segmentation to limit lateral movement if compromise is discovered.

The broader implication reinforces that supply chain security requires continuous monitoring of third-party software, regular penetration testing of critical dependencies, and strict code review processes. Organizations cannot rely solely on their vendors' security posture. North Korean threat actors have demonstrated consistent capability and intent to exploit these trust relationships for long-term network access.