Jade Sleet's macOS backdoors showed up on an IT-services MacBook. The crypto heist was optional.
SentinelOne hunted FLATROOF and ROOFDECK after LayerZero and found a DevOps engineer in India. Delivery on this host is unproven. Hunt Cursor children and HashiCorp typosquats.
Bottom line up front
CONFIRMED SentinelOne published, on 18 September 2026, a second victim for the macOS backdoors FLATROOF (also macOS.Gaslight) and ROOFDECK. The host was an Apple Silicon MacBook belonging to a DevOps engineer at an India-based IT services provider with no cryptocurrency business. The Hacker News carried the English amplification this morning.
The actor cluster is SentinelOne’s: TraderTraitor, also tracked as Jade Sleet, UNC4899, PUKCHONG, described as a financially motivated DPRK-aligned Lazarus subgroup. RWP is not independently attributing. Google and Mandiant are credited as partners on the toolset. The same families were used in the March–April 2026 LayerZero / KelpDAO intrusion.
Do not collapse three facts.
- This victim is not LayerZero. SentinelOne found it by hunting the implants, not by walking a crypto incident.
- Initial access on this MacBook is UNKNOWN. Hashes were on disk by 18 March 2026. First observed execution was 29 March, parented by Cursor. SentinelOne cannot prove the delivery path on this host.
- The campaign method, elsewhere, is a fake job interview that ships a weaponized
.terraform.lock.hcl.terraform initthen pulls a provider from a typosquat of HashiCorp’s registry. That is CONFIRMED as the LayerZero path and as the lure set SentinelOne recovered. It is not proven for the Indian host.
CISA KEV catalog 2026.09.18 (count 1716, still the live feed this morning) has no row for these implants. There is nothing to wait for.
| Fact | Record |
|---|---|
| Actor (vendor cluster) | TraderTraitor / Jade Sleet / UNC4899 / PUKCHONG |
| Victim (this report) | Unnamed India-based IT services firm; one Apple Silicon DevOps MacBook |
| Families | FLATROOF (SystemUpdate), ROOFDECK (iSync, later stripped loginwindow) |
| First on disk | 18 March 2026 |
| First execution | 29 March 2026, via Cursor opening ~/DevOps-Automation/cloudshield |
| Last observed C2 | 1 June 2026 to grenight[.]com |
| Named follow-on customer compromise | UNKNOWN. SentinelOne assesses the intrusion did not yield enough value to keep |
| OT / process impact | None claimed |
| KEV | Absent from 2026.09.18 |
This is not a re-run of [yesterday’s Conductor GraalVM RCE](/posts/2026-09-20-conductor-cve-2026-58138-graalvm-rce/). Different product, different clock, different class of access.
What happened
SentinelOne’s hunt started from the LayerZero disclosure. After that public report, the lab looked in its own telemetry for the same ARM64 Rust backdoors and found one more host. Authors: Albert Priego, Alex Delamotte, Matej Havranek. The write-up is paired with a LABScon 2026 talk, Don’t Call Us, We’ll Call Your APIs.
The engineer ran Terraform and Ansible against AWS, OVH, and OpenStack on working days. The laptop held cloud credentials and source-control access. SentinelOne’s comparison is LayerZero’s “Developer1”: the value of the target is whatever the laptop can reach.
Timeline, as published — SentinelOne telemetry, not a reconstructed campaign diary:
| When (UTC) | What | Status |
|---|---|---|
| 18 Mar 2026 | FLATROOF and ROOFDECK hashes on disk | CONFIRMED (S1) |
| 25–28 Mar | Cursor in daily use; no malicious activity seen | CONFIRMED (S1 negative) |
| 29 Mar 05:00 | cloudshield workspace opened in Cursor; both implants launched with nohup and --type=renderer | CONFIRMED |
| 29 Mar 05:00:55 | C2: SystemUpdate → technicais / 176.97.114[.]232; iSync → hubpage / 45.11.59[.]140; Telegram seconds later | CONFIRMED |
| 29 Mar 05:00:58 | xattr -rd com.apple.quarantine and chmod +x on iSync | CONFIRMED Gatekeeper bypass |
| 30 Mar–19 Apr | Beaconing gated on Cursor sessions; quiet when Cursor is off | CONFIRMED |
| 13 Apr | Engineer clones terraform-candidate-repo via GitHub Desktop | CONFIRMED clone; after first execution |
| 20 Apr | New stripped ROOFDECK (loginwindow) staged from 85.137.56[.]10, C2 grenight[.]com; old binaries deleted | CONFIRMED. One day after LayerZero’s public statement. Causal link is ASSESSED, not proven |
| 3 May–1 Jun | loginwindow beacons to grenight[.]com | CONFIRMED |
| 17 Jun | loginwindow moved to Trash | CONFIRMED |
The 13 April clone is not the origin story on this host. The implants were already executing two weeks earlier. Treat the Terraform lure as campaign tradecraft, not as the proven vector for this MacBook.
Campaign lure set, recovered from GitHub:
- Repos:
gtn-candidate-repo(LayerZero),Northwind-IAC,novacart-interview,terraform-candidate-repo - Typosquat provider domains:
registry.hashicorp-aws[.]com,registry.hashicorp-aws[.]io,registry.hashicorp-terraform[.]io - Mechanism: a weaponized
.terraform.lock.hclthat makes Terraform treat the attacker registry as the source of truth
One candidate left a note that they had removed a typosquatted provider. Awareness works. It is not a control.
Why it matters
The interesting fact is not that DPRK operators steal cryptocurrency. It is that the same implants and the same interview packaging landed on an IT-services DevOps endpoint that had no Web3 business.
A developer laptop is a control plane. Terraform, Ansible, AWS, OVH, OpenStack, and source control are how that engineer’s employer — and that employer’s customers — get built. SentinelOne’s conclusion, which we will not inflate: not every foothold becomes a $292 million mint event. The LayerZero / KelpDAO theft remains the high-value case. This one, they assess, was not worth keeping.
That is not comfort. It is a hunting problem. The dwell on this host ran from mid-March into June. Beaconing was gated on an IDE. Persistence looked like Apple: SystemUpdate under com.apple.iTunesCloud, iSync under com.apple.internal.ck, later loginwindow under com.apple.appleaccountd, LaunchAgent with --type=renderer.
ROOFDECK’s C2 discovery uses Nostr relays and an operator profile’s website field as a dead-drop, with Pastebin-style fallback and a pinned TLS certificate minted by mkcert on a QEMU box as user ub. FLATROOF exfiltrates over Telegram. Indicator-based blocking of a single domain does not close that channel.
Do not write an OT event. SentinelOne did not identify industrial-control, SCADA, or physical-process impact. An IT-services firm may have industrial customers. That is UNKNOWN. Inventory whether DevOps laptops can reach those customers. Do not invent a plant incident.
Who / what is affected
| Asset | What to assume | Status |
|---|---|---|
| Apple Silicon macOS DevOps / cloud / FinTech engineering endpoints | In scope for this cluster’s interview lures and these two families | CONFIRMED toolset; this report is one extra victim |
| Corporate MacBooks used for external take-home coding tests | Policy gap. SentinelOne recommends against it | ASSESSED control, not a CVE |
Terraform projects whose .terraform.lock.hcl names a registry other than registry.terraform.io | Treat as hostile until proven otherwise | CONFIRMED lure mechanism (LayerZero + recovered repos) |
| Official Terraform registry modules | Can still be malicious; lockfile domain is necessary, not sufficient | CONFIRMED caveat from S1 |
Cursor / other IDE child processes that are unsigned binaries in $HOME/Library | Hunt class | CONFIRMED on this host |
| Downstream customers of the unnamed Indian IT-services firm | UNKNOWN. No customer list. No confirmed follow-on | UNKNOWN |
| Crypto / Web3 engineering orgs | Still the historical target set (LayerZero / KelpDAO) | CONFIRMED background, not this victim |
Technical context
Both implants are ARM64, Rust, built for macOS.
FLATROOF (~/Library/com.apple.iTunesCloud/SystemUpdate, SHA-1 02df07a173ab03b82a4fb6a08973fff8b1467f28): first-stage collection and loader. Commands include shell, upload (Telegram attach), kill, id, stop. A bundled Python harvester takes Chrome, Brave, Firefox, and Safari data, shell history, system_profiler, ps aux, installed apps, and a raw login.keychain-db. On start it strips quarantine from ROOFDECK.
ROOFDECK (~/Library/com.apple.internal.ck/iSync, SHA-1 c491d477dbe0ae04e9aed9dbe237144c03f73ec4; later ~/Library/com.apple.appleaccountd/loginwindow, SHA-1 5728b11d30586bbfc1d8bd12df1c722a06e767a2): second-stage. Config at ~/.config/.repl_history. First-run C2 comes from Nostr profile lookup (api.nostr[.]watch/v1/online plus a hardcoded relay list: relay.damus[.]io, nos[.]lol, nostr[.]mom, relay.snort[.]social, and others). Commands are RSA-signed. The implant reimplements file and directory operations rather than calling the obvious shell — a pattern SentinelOne maps to Lazarus LightlessCan. Persistence: ~/Library/LaunchAgents/ plist, RunAtLoad, --type=renderer. HTTPS tasking path /app_version. IPC pipe /private/tmp/.pipe-airway.
mkcert artifact (hunt this, do not treat as unique to one domain):
- Subject/Issuer:
O=mkcert development CA,OU=ub@ub-Standard-PC-Q35-ICH9-2009,CN=mkcert ub@ub-Standard-PC-Q35-ICH9-2009 - Serial
1cd6d13ff15adbf7a42025d10ec99b4a - SHA-256
4b2d3e8ccce8920a6d01e7d02b84236545a20e5f754b3eec253f8b416b731daa - Validity 2025-06-20 → 2035-06-20
ATT&CK mapping (defensive, from observed behavior — not a complete actor playbook): T1566.002 (interview / coding-challenge lure), T1195.002 (malicious Terraform provider), T1059.004 / T1059.006 (shell, Python harvester), T1553.001 (quarantine attribute), T1543.001 (Launch Agent), T1036 (Apple-looking names, --type=renderer), T1555.001 / T1555.003 (keychain, browsers), T1102 (Telegram, Nostr dead-drop), T1071.001 (HTTPS /app_version), T1070.004 (implant deletion on 20 April).
Threat / exploitation status
| Claim | Grade |
|---|---|
| FLATROOF + ROOFDECK on this IT-services MacBook, Mar–Jun 2026 | CONFIRMED (SentinelOne telemetry) |
| Same families as LayerZero / KelpDAO | CONFIRMED (S1; LayerZero / Mandiant names) |
| TraderTraitor / Jade Sleet / UNC4899 as the operator | CONFIRMED as SentinelOne’s cluster; RWP confidence moderate pending a second independent public technical match |
| Terraform lock-file as delivery on this host | UNKNOWN |
| Terraform lock-file as campaign lure | CONFIRMED (recovered repos + LayerZero path) |
| Current (September) active beaconing on this host | Not in the published telemetry after 1 June; 17 June binary to Trash |
| Broad IT-services targeting as a new program | ASSESSED. One extra victim does not prove a sector campaign |
| Ransomware-Known | Not a CISA field. UNKNOWN |
| In CISA KEV | No |
X discussion of the SentinelOne paper (18–21 September) is amplification, not measurement. RWP used it as discovery only.
What defenders should do
Today, on macOS developer endpoints — especially anyone with cloud or VCS admin:
- Hunt the paths and hashes above. Unsigned or ad-hoc-signed Mach-O in
$HOME/Library/com.apple.*that is not an Apple-shipped binary is the ticket, not the C2 domain of the week. - Hunt LaunchAgents whose
ProgramArgumentsinclude--type=rendererand a binary that is not Chromium/Electron. - Hunt IDE telemetry: Cursor, VS Code, JetBrains spawning
nohupchildren under those Library paths. On this host the implants only beaconed while Cursor was running. - Hunt
~/.config/.repl_historyas a ROOFDECK config,/private/tmp/.pipe-airway, and$TMPDIR/tmp*.lock. - Pull TLS inspection or certificate inventory for the mkcert
ub@ub-Standard-PC-Q35-ICH9-2009subject. SentinelOne listed related names includinggrenight[.]com,storage.hubpage[.]cloud,technicais.sytes[.]net,mactroubleshoots[.]pro,heyhay[.]online,galaxy-royal[.]online. - Inventory
.terraform.lock.hclacross developer home directories and CI. Flag any provider source host that is notregistry.terraform.io. The three typosquats above are sufficient to start; they are not a complete list. - Ask engineers — in a non-punitive channel — whether they ran an external take-home or “interview task” repo on a corporate Mac in 2026. Telemetry will not label a recruiter.
- If you find the implants: treat cloud keys, VCS PATs, browser sessions, and the login keychain as burned. Rotate. Do not call the ticket closed on a binary delete; S1 watched the operator delete the first stage themselves on 20 April and keep a stripped successor.
Policy that actually changes the intercept:
- Corporate workstations are not for external coding interviews. If you cannot enforce it, you do not have it.
- Train DevOps on lockfile registries the same way you train them on
curl | sh. One candidate already caught the HashiCorp typosquat. That is the cheap control.
Do not publish or replay exploit steps for the Terraform provider, the Nostr dead-drop, or the implants. The hashes, paths, and registry hostnames are enough to hunt.
RWP assessment
Score 8.4. High confidence on the host facts. Moderate confidence on the cluster name. Low confidence that this is a new mass IT-services campaign.
Why this outranked the rest of the window: it is the first Daily Top on this victim expansion; the access class is developer-to-cloud, which is how enterprises actually get run; the primary source is a lab paper with timestamps, hashes, and a honest UNKNOWN on delivery. CISA did not add a KEV row over the weekend — catalog still 2026.09.18 — so there is no federal clock hiding the story.
Runner-up, not selected: Checkmarx’s indexed-btree npm campaign (17 September, BleepingComputer 20 September) is a real supply-chain shift — malware in BTree.prototype.set() instead of install scripts, Checkmarx’s “almost 2 million weekly downloads” claim, packages subsequently pulled. It loses on attribution quality and on “what a CISO does Monday morning” versus a named DPRK toolset on a DevOps Mac. CVE-2026-90817 in REDCap (CNA published 20 September, CVSS 9.8, patch floors 16.0.49 / 17.3.10 / 17.4.4) is unauthenticated RCE through survey passthrough plus data-import, but the CNA requires a valid public survey hash and does not claim exploitation. Vanderbilt / REDCap is a clinical-research surface; we already covered UNC6508’s REDCap espionage as a June backfill. No KEV row. CVE-2026-90822 / 90823 in FatPipe MPVPN (Securifera, 21 September) are unauthenticated root on an EOL image, management interface disabled by default. No in-wild claim. Blackpoint’s ChainScript RAT (21 September) is a new ClickFix / EtherHiding family. Cybercrime, Windows, Polygon resolver — crowded pattern, weaker enterprise control-plane.
We are not scoring “DPRK plus Mac” as automatically 9. The last beacon in the paper is June. The decision this morning is hunt-and-policy, not emergency patching of a KEV appliance.
What we are watching
- A second independent lab or national CERT matching FLATROOF / ROOFDECK on non-crypto victims.
- Whether CISA, or a vendor PSIRT, ever files a KEV-class row. Unlikely for a custom implant; still check the feed.
- Terraform official-registry abuse, which S1 already warns is possible even when the hostname is correct.
- Collapse risk: WaterPlum (job-seeker malware, law-enforcement advisory last week) is a different DPRK cluster. Do not merge the names.
- REDCap CVE-2026-90817 moving from advisory to exploitation. Survey-hash prerequisite keeps it off today’s lead. It does not make internet-facing REDCap safe.
Sources
Primary: SentinelOne, 18 September 2026. Secondary amplification: The Hacker News, 21 September 2026. KEV negative: CISA catalog 2026.09.18. Runner-up primaries as linked in the header. X used as discovery only.
Sources
- SentinelOne — Don’t Call Us, We’ll Call Your APIs
- The Hacker News — Jade Sleet Linked to Indian IT Provider Breach
- CISA — KEV JSON feed catalog 2026.09.18
- CISA — Known Exploited Vulnerabilities Catalog
- The Hacker News — ClickFix Lures Deploy ChainScript RAT (Blackpoint APG)
- Checkmarx Zero — npm btree malware campaign
- CVE — CVE-2026-90817
- NVD — CVE-2026-90817
- Securifera — One Login, Two RCEs CVE-2026-90822 CVE-2026-90823