Return to Threats

Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

thehackernews.com 2026-09-21 AI supply chain High

What Happened

The North Korean threat actor known as Jade Sleet has been attributed to the compromise of an India-based "much smaller organization" in the information technology (IT) services industry, once again highlighting how the adversary continues to target developers to breach target networks. Cybersecurity company SentinelOne, which disclosed details of the activity, said it involved the use of Apple

Why It Matters

According to the report, the North Korean threat actor Jade Sleet compromised a smaller India-based IT services provider, using custom backdoors (FLATROOF and ROOFDECK) and targeting developers as an entry point into wider target networks. The disclosure by SentinelOne highlights how attacking smaller suppliers and developer environments can provide a path to higher-value downstream victims. From a RealGround perspective, this illustrates AI supply chain risk: compromised IT service vendors and developer tooling can become conduits for malicious code, model tampering, or surreptitious integration of backdoors into AI systems. Organizations should treat third-party IT and development partners as part of their AI supply chain, enforcing SBOM, code integrity checks, and continuous security assessments to prevent cascading compromise into AI-powered services.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/09/jade-sleet-linked-to-indian-it-provider.html

Talk to AI CISO