Skip to content
feed: live
>_0dayNews
supply chain

Jade Sleet Hits Indian IT Firm with Custom Backdoors

North Korea's Jade Sleet has compromised an India-based IT services provider, deploying the FLATROOF and ROOFDECK backdoors to position inside customer networks.

Jade Sleet Hits Indian IT Firm with Custom Backdoors
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
loopNadia "Loop" Park·Published ·2 min read

IT services companies carry persistent, trusted access into their customers’ environments. That is the whole point. It is also why Jade Sleet keeps targeting them.

Jade Sleet, the North Korean threat actor tracked by Google TAG and others under adjacent cluster names, has been attributed to the compromise of an India-based IT services provider, according to The Hacker News on September 21. The firm is described as a “much smaller organization” in the IT services industry, consistent with Jade Sleet’s documented pattern of staging attacks through managed service and IT support providers rather than striking large enterprises directly.

Two backdoors, FLATROOF and ROOFDECK, were found in the compromised environment. Both are attributed to Jade Sleet. The full technical breakdown is in The Hacker News reporting; what matters operationally is that both tools are designed for persistence and lateral access inside enterprise infrastructure, not for immediate smash-and-grab.

Why IT providers

The appeal is not subtle. An IT services company typically has some level of remote management access into customer systems: VPN credentials, RMM agents, helpdesk privileges granted years ago and rarely audited since. Compromising the provider before pivoting downstream means the attacker appears in customer logs with a trusted source address and a valid credential, sometimes with rights the customer handed over and forgot about.

This is the same underlying attack surface exploited via the ScreenConnect worm campaign in September and in the SolarWinds supply chain intrusion several years prior. The vector differs; the logic does not.

North Korea’s interest in Indian IT services companies fits into a broader pattern. Researchers tracking Jade Sleet note the group’s consistent focus on cryptocurrency platforms, financial infrastructure, and technology supply chains, with objectives that mix intelligence collection and revenue generation. The WaterPlum campaign covered here last week used a different delivery method against individual targets, but the underlying sponsor is the same program.

What to check now

If your organization uses a third-party IT services provider, including one based in APAC, this is the moment to pull the access audit: which credentials or agent software does that provider hold in your environment, which systems those credentials can reach, and when they were last rotated. Third-party access reviews are not a North Korea-specific precaution. They are standard hygiene, and this case is a concrete reason to run one if it has been a while.

The Hacker News article carries the malware family analysis and IOC detail for defenders who need it.

Found this useful? Share it.