The North Korean threat actor Jade Sleet has leveraged two newly discovered macOS backdoors, FLATROOF and ROOFDECK, to compromise an Indian information technology services provider, according to analysis from cybersecurity firm SentinelOne. The operation marks a strategic evolution in the group's toolkit and highlights the acute risks posed by supply-chain attacks targeting developer environments.

SentinelOne's investigation found that Jade Sleet, also known under designations like Lazarus Group, breached what it described as a "much smaller organization" within the Indian IT services sector. The group has a well-documented history of compromising software developers and IT firms as a stepping stone to infiltrate the networks of their downstream clients. This latest campaign demonstrates a continued, high-impact reliance on this tactic.

The core technical finding is the deployment of FLATROOF and ROOFDECK, two sophisticated backdoors designed specifically for Apple's macOS. Built for persistence and stealth, these tools enable attackers to maintain long-term access to compromised machines. The shift to dedicated macOS malware is significant, indicating that Jade Sleet is adapting to environments where both Windows and macOS are common, likely to evade security monitoring tuned for traditional Windows threats.

According to SentinelOne, the attack chain began with the compromise of developer workstations at the Indian IT firm. By targeting a trusted supplier, Jade Sleet establishes a legitimate-seeming access vector into the digital ecosystems of that provider's own clients. This method effectively circumvents perimeter defenses, as connections originating from a known business partner are typically trusted.

This incident underscores the persistent and critical nature of third-party risk. An organization's security is directly linked to the practices of its vendors, contractors, and offshore partners. A breach at a smaller, less scrutinized IT services company can serve as the gateway for major intrusions at larger client organizations.

While the SentinelOne report centers on an Indian provider, the broader implications extend across the Asia-Pacific region. For Hong Kong-based companies, especially in finance, technology, and professional services that depend on managed IT services or offshore development, this attack pattern is directly applicable. The incident stresses the need for rigorous, ongoing assessment of the security controls employed by external providers. Organizations should treat their vendors' networks as an extension of their own attack surface, demanding transparency on security protocols, access controls, and incident response readiness.

The Jade Sleet campaign shows adversaries are actively refining their tools to target the trusted relationships modern business relies on. Effective defense requires a fundamental shift toward applying zero trust principles to third-party engagements and treating any compromise within the supply chain as a critical enterprise risk.


根據網絡安全公司 SentinelOne 的分析,朝鮮威脅行為者 Jade Sleet 利用了兩款新發現的 macOS 後門 FLATROOF 和 ROOFDECK,入侵了一家印度信息技術服務供應商。此次行動標誌著該組織工具包的戰略性演進,並凸顯了針對開發者環境的供應鏈攻擊所帶來的嚴峻風險。

SentinelOne 的調查發現,又名 Lazarus Group 等代號的 Jade Sleet 入侵了一家其描述為「規模小得多的組織」的印度 IT 服務公司。該組織有詳實記錄的歷史,曾以軟件開發商和 IT 公司為跳板,滲透其下游客戶的網絡。此次最新行動顯示其持續且高度依賴此策略。

核心技術發現是部署了 FLATROOF 和 ROOFDECK,這兩款專為蘋果 macOS 設計的複雜後門。這些工具專為持久性和隱蔽性而建,使攻擊者能長期維持對受感染機器的訪問權限。轉向專用 macOS 惡意軟件意義重大,表明 Jade Sleet 正在適應同時普遍使用 Windows 和 macOS 的環境,可能旨在規避針對傳統 Windows 威脅配置的安全監控。

SentinelOne 指出,攻擊鏈始於入侵該印度 IT 公司的開發人員工作站。通過瞄準受信任的供應商,Jade Sleet 建立了一個看似合法的訪問向量,以進入該供應商自身客戶的數字生態系統。此方法有效繞過了邊界防禦,因為源自已知業務合作夥伴的連接通常被信任。

此次事件凸顯了第三方風險的持續性和關鍵性。一個組織的安全性與其供應商、承包商和離岸合作夥伴的實踐直接相關。一家規模較小、受較少審查的 IT 服務公司發生的安全漏洞,可能成為主要客戶組織遭受重大入侵的門戶。

雖然 SentinelOne 報告集中於一家印度供應商,但更廣泛的影響延伸至整個亞太區。對於依賴託管 IT 服務或離岸開發的香港公司,尤其在金融、科技和專業服務領域,這種攻擊模式直接適用。此次事件強調了對外部供應商採用的安全控制措施進行嚴格、持續評估的必要性。組織應將其供應商的網絡視為自身攻擊面的延伸,要求在安全協議、訪問控制和事件應對準備方面保持透明度。

Jade Sleet 的行動表明,對手正積極改進其工具,以瞄準現代商業所依賴的信任關係。有效防禦需要根本性的轉變,即將 zero trust 原則應用於第三方合作,並視供應鏈內任何入侵為關鍵企業風險。

新聞來源 / Original News Source