Interestana
Home/News/Jade Sleet Linked to Indian IT Provider Breach
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Jade Sleet Linked to Indian IT Provider Breach

Jade Sleet Linked to Indian IT Provider Breach

The North Korean threat actor identified as Jade Sleet has been linked to the compromise of an Indian information technology (IT) services organization, a "much smaller organization" according to cybersecurity firm SentinelOne. This incident underscores the persistent strategy of Jade Sleet in targeting software developers as a vector to infiltrate broader target networks. SentinelOne's analysis, disclosed on March 12, 2024, detailed the adversary's modus operandi, which involved the exploitation of Apple devices, specifically Macs, to gain initial access.

The threat actor employed a sophisticated two-stage backdoor system. The first stage, dubbed FLATROOF, is a downloader that establishes persistence and fetches the second-stage payload. FLATROOF is designed to be stealthy, operating with minimal system impact to avoid detection. It is capable of executing commands, downloading additional files, and communicating with its command-and-control (C2) infrastructure. This initial foothold allows Jade Sleet to maintain a presence within the compromised network and prepare for further malicious activities.

The second-stage backdoor, ROOFDECK, is a more advanced tool that provides extensive remote access and control capabilities. ROOFDECK is capable of executing arbitrary commands, exfiltrating data, and deploying further malware. SentinelOne's research indicates that ROOFDECK was used to maintain long-term access and potentially conduct espionage or intellectual property theft. The use of these custom backdoors highlights Jade Sleet's technical proficiency and their commitment to developing tailored tools for their operations.

SentinelOne's report also noted that the compromised IT provider was targeted due to its role in developing software, making its employees and infrastructure valuable targets for supply chain attacks. By compromising an IT service provider, Jade Sleet could potentially gain access to the provider's clients, thereby expanding their reach and impact significantly. This tactic is a common strategy for advanced persistent threat (APT) groups, allowing them to achieve greater impact with a single compromise. The investigation into the specifics of the initial access vector and the full extent of the data exfiltration is ongoing, but the attribution to Jade Sleet and the use of the FLATROOF and ROOFDECK backdoors provide critical insights into the threat actor's capabilities and objectives.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next