Jade Sleet Compromises Indian IT Services Firm, Deploys FLATROOF and ROOFDECK Backdoors
What Happened — North‑Korean threat group Jade Sleet infiltrated a small India‑based IT services provider that supplies development talent to global enterprises. SentinelOne observed the actors installing two custom backdoors, dubbed FLATROOF and ROOFDECK, and using the compromised environment to pivot into downstream customer networks.
Why It Matters for Trust & Control Assurance
- Demonstrates how a single weak third‑party relationship can become the foothold for a nation‑state campaign, testing the effectiveness of continuous vendor‑risk monitoring.
- Highlights the need for auditable evidence that third‑party access is limited, logged, and reviewed against a control‑objective such as “Manage and monitor external service provider access”.
- Aligns with the third‑party risk management capability: real‑time oversight, evidence collection, and defensible audit trails are precisely what mitigate this supply‑chain scenario.
Who Is Affected
- IT services and software development firms (MSPs, outsourcing providers).
- Enterprises that rely on external developers or managed services for critical applications.
Recommended Actions
- Inventory all third‑party service providers and map the data, systems, and privileges they hold.
- Verify that each provider follows a documented access‑control policy and that logs are retained for continuous monitoring.
- Conduct a focused audit of the compromised provider’s security posture and demand remediation evidence before re‑enabling access.
- Integrate the findings into your continuous control‑assurance platform to maintain a defensible audit trail.
Technical Notes
- Attack vector: third‑party dependency – compromised development environment used as a launchpad.
- Backdoors: custom implants “FLATROOF” and “ROOFDECK” (binary‑level persistence, remote command execution).
- Data types: source code repositories, build pipelines, and potentially credential stores for downstream customers.
Source: The Hacker News – https://thehackernews.com/2026/09/jade-sleet-linked-to-indian-it-provider.html