Canadian Cyber Security Journal
SOCIAL:
Filed under: Trends

North Korea’s Jade Sleet Hackers Breach an IT Provider Through a Developer’s Laptop

What Happened

Researchers attribute a breach of a small India-based IT services provider to Jade Sleet, a North Korean hacking group also tracked as TraderTraitor, PUKCHONG, Slow Pisces, and UNC4899. Attackers compromised a DevOps engineer’s MacBook and deployed two backdoors: FLATROOF, which uses Telegram for command and control and steals browser data, terminal history, and macOS keychain files through a Python module, and ROOFDECK, which uses the decentralized Nostr protocol for command and control and supports remote shell access and lateral movement. Both tools previously surfaced in the group’s early 2026 attack on Web3 bridge platform KelpDAO. Jade Sleet has a long record of targeting developers to reach cryptocurrency and Web3 organizations, including the 2025 theft of roughly $1.5 billion from crypto exchange Bybit through a compromised developer environment at wallet infrastructure provider Safe. Read more from The Hacker News.

Why This Matters for Canadian Organizations

Canada hosts a sizable cryptocurrency and Web3 development sector, along with IT services firms serving clients across finance and technology, both squarely inside Jade Sleet’s established targeting pattern. The group’s method, compromising an individual developer’s personal machine rather than corporate infrastructure directly, sidesteps many enterprise security controls entirely and highlights a gap between how organizations secure company-issued devices and how they secure the personal or lightly managed machines developers sometimes use for side projects or contract work. The Canadian Centre for Cyber Security has named North Korean state-sponsored actors a persistent threat to the technology and financial sectors, and this incident fits directly into this assessment.

What to Do

Organizations employing developers with access to source code, credentials, or deployment pipelines should require endpoint protection and monitoring on any device used for work, company-issued or not, and should train developers to recognize recruitment-style social engineering, a common Jade Sleet entry point. Security teams should hunt for indicators tied to FLATROOF and ROOFDECK, including unexpected Telegram-based network traffic and Nostr protocol connections, and should review access logs for any DevOps or CI/CD account tied to a compromised developer machine.

Enjoy this article? Don’t forget to share.