The record
Written from the 1 report below. Nothing here is unsourced.
- The North Korean threat actor Jade Sleet breached an India-based IT services firm by targeting a DevOps engineer.
- Attackers deployed two macOS-specific backdoors named FLATROOF and ROOFDECK to steal sensitive data and maintain persistence.
- This group frequently uses social engineering and weaponized software dependencies to gain initial access to developer systems.
- The incident highlights the growing risks to corporate networks when developer endpoints are compromised.
What to watch next
- Monitoring for updated versions of FLATROOF and ROOFDECK malware
- Analysis of additional supply chain compromises targeting DevOps environments
- Developments in North Korean threat actor social engineering lures
Who said what3
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Albert Priego
security
1 quote · 1 outlet
“The GitHub repository themes for coding project lures are designed as infrastructure engineering projects related to the company that the DPRK actors are posing as”
In the article
…threat actors, to target job seekers from the companies that are breached over the course of the attack. Targeted individuals have been found to work in the DevOps, cryptocurrency, or financial technology space. " The GitHub repository themes for coding project lures are designed as infrastructure engineering projects related to the company that the DPRK actors are posing as ," security researchers Albert Priego, Alex Delamotte, and Matej Havranek said. Some of the repositories observed are listed below - - gtn-candidate-repo (used in the KelpDAO incident) - Northwind-IAC -…
Alex Delamotte
security
1 quote · 1 outlet
“The GitHub repository themes for coding project lures are designed as infrastructure engineering projects related to the company that the DPRK actors are posing as”
In the article
…threat actors, to target job seekers from the companies that are breached over the course of the attack. Targeted individuals have been found to work in the DevOps, cryptocurrency, or financial technology space. " The GitHub repository themes for coding project lures are designed as infrastructure engineering projects related to the company that the DPRK actors are posing as ," security researchers Albert Priego, Alex Delamotte, and Matej Havranek said. Some of the repositories observed are listed below - - gtn-candidate-repo (used in the KelpDAO incident) - Northwind-IAC -…
Matej Havranek
security
1 quote · 1 outlet
“The GitHub repository themes for coding project lures are designed as infrastructure engineering projects related to the company that the DPRK actors are posing as”
In the article
…threat actors, to target job seekers from the companies that are breached over the course of the attack. Targeted individuals have been found to work in the DevOps, cryptocurrency, or financial technology space. " The GitHub repository themes for coding project lures are designed as infrastructure engineering projects related to the company that the DPRK actors are posing as ," security researchers Albert Priego, Alex Delamotte, and Matej Havranek said. Some of the repositories observed are listed below - - gtn-candidate-repo (used in the KelpDAO incident) - Northwind-IAC -…
Coverage1
All filed from India
Named India · North Korea · Apple · Bybit · HashiCorp · KelpDAO · LayerZero · Safe{Wallet} · GitHub · Jade Sleet · Microsoft · SentinelOne
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
