research
Published 2026-09-18
Verified 2026-09-21

SentinelOne: Jade Sleet/TraderTraitor FLATROOF+ROOFDECK on Indian IT DevOps Mac (Terraform interview lures)

SentinelOne Labs (Albert Priego, Alex Delamotte, Matej Havranek; 18 September 2026) documents a further victim of North Korean TraderTraitor / Jade Sleet (also PUKCHONG, Slow Pisces, UNC4899) after the April 2026 LayerZero / KelpDAO theft disclosure. Primary: an India-based IT services provider (not crypto-affiliated) compromised via an Apple Silicon DevOps engineer’s MacBook holding Terraform/Ansible reach into AWS, OVH and OpenStack plus source-control credentials. Same macOS ARM64 Rust backdoors as LayerZero: FLATROOF (aka macOS.Gaslight; on-disk appearance as SystemUpdate under ~/Library/com.apple.iTunesCloud/) and ROOFDECK (as iSync under ~/Library/com.apple.internal.ck/). Telemetry: both implants on disk from 18 March 2026, dormant until 29 March when Cursor launched them seconds after opening a cloudshield workspace; FLATROOF strips Gatekeeper quarantine from ROOFDECK before exec. Initial access pattern across the campaign wave: Contagious Interview–style job lures via GitHub coding projects with weaponised .terraform.lock.hcl pointing at attacker “HashiCorp” provider domains (registry.hashicorp-aws[.]com / .io / registry.hashicorp-terraform[.]io) so terraform init pulls malicious modules. Distinct from desk card acsc-waterplum-contagious-interview-20260918 (WaterPlum / Contagious Interview joint advisory) — overlapping lure tradecraft, different DPRK cluster and tooling. Amplify: The Hacker News 21 September 2026. No CVE.

Product
TraderTraitor/Jade Sleet macOS backdoors FLATROOF (Gaslight) + ROOFDECK; Terraform interview-lure supply chain
Versions
n/a (malware / TA TTPs; ARM64 macOS Rust implants)
Exploited in Australia?
unknown
Patch to
Treat unexpected Terraform provider domains / lockfile diffs as malicious; do not run terraform init from interview coding projects on corporate Macs; hunt FLATROOF/ROOFDECK paths (SystemUpdate, iSync under Library); rotate cloud and SCM credentials from any host that opened such lures; keep Contagious Interview / WaterPlum joint-advisory hygiene (ACSC) in parallel — distinct actor cluster.

Primary: SentinelOne Labs — TraderTraitor / FLATROOF+ROOFDECK on non-crypto IT victim (18 Sep 2026) · Vendor: SentinelOne Labs primary analysis · The Hacker News — Jade Sleet / FLATROOF+ROOFDECK amplify (21 Sep 2026)

tech identity cloud ai