HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

North Korean Actor Jade Sleet Compromises Indian IT Services Firm, Deploys FLATROOF and ROOFDECK Backdoors

Jade Sleet infiltrated a small Indian IT services provider and installed custom backdoors, enabling lateral movement into client networks. The incident underscores the importance of continuous third‑party risk monitoring and auditable access controls for supply‑chain resilience.

Verisq™ Intelligence · 📅 September 21, 2026 · 📰 thehackernews.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
1 recommended
📰
Source
thehackernews.com

Jade Sleet Compromises Indian IT Services Firm, Deploys FLATROOF and ROOFDECK Backdoors

What Happened — North‑Korean threat group Jade Sleet infiltrated a small India‑based IT services provider that supplies development talent to global enterprises. SentinelOne observed the actors installing two custom backdoors, dubbed FLATROOF and ROOFDECK, and using the compromised environment to pivot into downstream customer networks.

Why It Matters for Trust & Control Assurance

  • Demonstrates how a single weak third‑party relationship can become the foothold for a nation‑state campaign, testing the effectiveness of continuous vendor‑risk monitoring.
  • Highlights the need for auditable evidence that third‑party access is limited, logged, and reviewed against a control‑objective such as “Manage and monitor external service provider access”.
  • Aligns with the third‑party risk management capability: real‑time oversight, evidence collection, and defensible audit trails are precisely what mitigate this supply‑chain scenario.

Who Is Affected

  • IT services and software development firms (MSPs, outsourcing providers).
  • Enterprises that rely on external developers or managed services for critical applications.

Recommended Actions

  1. Inventory all third‑party service providers and map the data, systems, and privileges they hold.
  2. Verify that each provider follows a documented access‑control policy and that logs are retained for continuous monitoring.
  3. Conduct a focused audit of the compromised provider’s security posture and demand remediation evidence before re‑enabling access.
  4. Integrate the findings into your continuous control‑assurance platform to maintain a defensible audit trail.

Technical Notes

  • Attack vector: third‑party dependency – compromised development environment used as a launchpad.
  • Backdoors: custom implants “FLATROOF” and “ROOFDECK” (binary‑level persistence, remote command execution).
  • Data types: source code repositories, build pipelines, and potentially credential stores for downstream customers.

Source: The Hacker News – https://thehackernews.com/2026/09/jade-sleet-linked-to-indian-it-provider.html

📰 Original Source
https://thehackernews.com/2026/09/jade-sleet-linked-to-indian-it-provider.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →