North Korean Hackers Target IT Developers With Fake Job Offers and macOS Backdoors
Security researchers at SentinelOne have linked North Korean threat actor Jade Sleet to the breach of a small India-based IT services company. The group, also known as TraderTraitor, PUKCHONG, and Slow Pisces, has a long history of targeting cryptocurrency and blockchain firms, including its suspected role in the theft of roughly $1.5 billion from Bybit earlier in 2025.
In this campaign, Jade Sleet used fake job interview lures, a tactic seen repeatedly among North Korean hacking groups, to target individuals working in DevOps, cryptocurrency, and financial technology roles. Victims were lured into downloading malicious coding projects disguised as infrastructure engineering tasks on GitHub. One method involved a tampered Terraform configuration file that silently pulled malware from an attacker-controlled domain when a common developer command was run.
The attack ultimately delivered two new Rust-based backdoors, FLATROOF and ROOFDECK, designed for ARM-based Apple Mac systems. These tools had previously been seen in an unrelated attack on a cryptocurrency bridge platform. Researchers noted that ROOFDECK's commands are cryptographically signed and verified before execution, showing a level of technical sophistication aimed at evading detection.