Published: · Region: Global · Category: cyber

Jade Sleet Hack of Indian IT Provider Shows North Korean Spies Targeting Apple Silicon Macs

A North Korean-linked group known as Jade Sleet is tied to a breach at an Indian IT provider through a DevOps engineer’s Apple Silicon MacBook, where rare malware dubbed FLATROOF and ROOFDECK was found with tools for remote control and data theft.

A compromise of a single developer’s MacBook has been linked to a wider breach at an Indian IT services firm, underscoring how one endpoint can open a path into global corporate networks.

A North Korean cyber-espionage group tracked as Jade Sleet is associated with the incident, according to a detailed technical investigation into the breach. The attackers are reported to have accessed a DevOps engineer’s Apple Silicon MacBook, where researchers uncovered previously undocumented malware families named FLATROOF and ROOFDECK. The tools are tailored to Apple’s M‑series architecture and are described as capable of command execution, remote shell access, persistence on the machine, and data theft.

Based on the public technical write-up, the MacBook appears to have served as the initial foothold inside the provider’s environment. A DevOps engineer typically works with code repositories, build systems and deployment tools, and may have access to customer environments. That kind of role can turn a successful compromise of one laptop into access to many interconnected systems. The available reporting doesn’t spell out how far the intruders moved from the engineer’s workstation or what damage they did downstream, but the presence of multi-purpose malware on a development machine points to an operation built for ongoing, quiet access rather than a quick smash-and-grab attack.

FLATROOF and ROOFDECK stand out less for novel techniques than for their focus on Apple Silicon hardware. Many organisations have treated newer Apple laptops as relatively low-risk because of their architecture and Apple’s security posture. On this MacBook, however, the malware reportedly provided the operators with a remote shell to run arbitrary commands, mechanisms to survive reboots, and functionality to exfiltrate data from the system. With that level of control, Jade Sleet’s operators could monitor activity on the engineer’s machine and potentially interfere with the code or configurations that support multiple clients.

For the Indian IT provider, the stakes go beyond a single endpoint infection. Firms in this sector often manage infrastructure, develop software and provide support for customers across industries and borders. If a state-linked group is sitting on a DevOps engineer’s MacBook, it can quietly influence software updates, configuration changes or infrastructure rollouts that touch many organisations. That turns what looks like a domestic breach into a transnational risk.

Jade Sleet is one of several names used in the security community for North Korean operators who combine espionage with financially motivated intrusions. Their known interests include cryptocurrency platforms, software supply chains and defence-related targets. The investment in bespoke Apple Silicon tooling suggests a deliberate effort to reach engineers and other high-value users whose Macs may not be monitored as closely as corporate Windows servers.

The case also highlights a blind spot in many companies’ defences. As Apple laptops spread among engineers and executives, security tools, logging and response plans often remain heavily focused on Windows. Developer machines in particular are frequently granted more freedom in the name of productivity, with fewer restrictions on what can be installed and run. This incident shows that North Korean-linked operators are prepared to write and deploy custom malware to exploit that gap.

Signals to track from here include whether investigators identify other victims running FLATROOF and ROOFDECK, any further attribution from national cyber agencies, and whether Apple or major security vendors introduce specific detections and hardening guidance for Apple Silicon Macs. If future reporting ties these tools to manipulation of software build or deployment pipelines, pressure will rise on IT service providers to treat developer endpoints as core security assets rather than secondary concerns.

Sources