Threat Intelligence

North Korean Hackers Target IT Developers With Fake Job Offers and macOS Backdoors

The Hacker News · 21 Sept 2026
Key Takeaway Businesses, especially in IT, tech, and crypto-adjacent sectors, should train developers to treat unsolicited job offers and unfamiliar code repositories with caution, and verify any third-party dependencies before running them.

Security researchers at SentinelOne have linked North Korean threat actor Jade Sleet to the breach of a small India-based IT services company. The group, also known as TraderTraitor, PUKCHONG, and Slow Pisces, has a long history of targeting cryptocurrency and blockchain firms, including its suspected role in the theft of roughly $1.5 billion from Bybit earlier in 2025.

In this campaign, Jade Sleet used fake job interview lures, a tactic seen repeatedly among North Korean hacking groups, to target individuals working in DevOps, cryptocurrency, and financial technology roles. Victims were lured into downloading malicious coding projects disguised as infrastructure engineering tasks on GitHub. One method involved a tampered Terraform configuration file that silently pulled malware from an attacker-controlled domain when a common developer command was run.

The attack ultimately delivered two new Rust-based backdoors, FLATROOF and ROOFDECK, designed for ARM-based Apple Mac systems. These tools had previously been seen in an unrelated attack on a cryptocurrency bridge platform. Researchers noted that ROOFDECK's commands are cryptographically signed and verified before execution, showing a level of technical sophistication aimed at evading detection.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.