Daily Top · Nation-State / Developer

Jade Sleet's macOS backdoors showed up on an IT-services MacBook. The crypto heist was optional.

SentinelOne hunted FLATROOF and ROOFDECK after LayerZero and found a DevOps engineer in India. Delivery on this host is unproven. Hunt Cursor children and HashiCorp typosquats.

RWP Ventures · 2026-09-21 · event 2026-09-18 · 11 min read · priority 8.4

Bottom line up front

CONFIRMED SentinelOne published, on 18 September 2026, a second victim for the macOS backdoors FLATROOF (also macOS.Gaslight) and ROOFDECK. The host was an Apple Silicon MacBook belonging to a DevOps engineer at an India-based IT services provider with no cryptocurrency business. The Hacker News carried the English amplification this morning.

The actor cluster is SentinelOne’s: TraderTraitor, also tracked as Jade Sleet, UNC4899, PUKCHONG, described as a financially motivated DPRK-aligned Lazarus subgroup. RWP is not independently attributing. Google and Mandiant are credited as partners on the toolset. The same families were used in the March–April 2026 LayerZero / KelpDAO intrusion.

Do not collapse three facts.

  1. This victim is not LayerZero. SentinelOne found it by hunting the implants, not by walking a crypto incident.
  2. Initial access on this MacBook is UNKNOWN. Hashes were on disk by 18 March 2026. First observed execution was 29 March, parented by Cursor. SentinelOne cannot prove the delivery path on this host.
  3. The campaign method, elsewhere, is a fake job interview that ships a weaponized .terraform.lock.hcl. terraform init then pulls a provider from a typosquat of HashiCorp’s registry. That is CONFIRMED as the LayerZero path and as the lure set SentinelOne recovered. It is not proven for the Indian host.

CISA KEV catalog 2026.09.18 (count 1716, still the live feed this morning) has no row for these implants. There is nothing to wait for.

FactRecord
Actor (vendor cluster)TraderTraitor / Jade Sleet / UNC4899 / PUKCHONG
Victim (this report)Unnamed India-based IT services firm; one Apple Silicon DevOps MacBook
FamiliesFLATROOF (SystemUpdate), ROOFDECK (iSync, later stripped loginwindow)
First on disk18 March 2026
First execution29 March 2026, via Cursor opening ~/DevOps-Automation/cloudshield
Last observed C21 June 2026 to grenight[.]com
Named follow-on customer compromiseUNKNOWN. SentinelOne assesses the intrusion did not yield enough value to keep
OT / process impactNone claimed
KEVAbsent from 2026.09.18

This is not a re-run of [yesterday’s Conductor GraalVM RCE](/posts/2026-09-20-conductor-cve-2026-58138-graalvm-rce/). Different product, different clock, different class of access.

What happened

SentinelOne’s hunt started from the LayerZero disclosure. After that public report, the lab looked in its own telemetry for the same ARM64 Rust backdoors and found one more host. Authors: Albert Priego, Alex Delamotte, Matej Havranek. The write-up is paired with a LABScon 2026 talk, Don’t Call Us, We’ll Call Your APIs.

The engineer ran Terraform and Ansible against AWS, OVH, and OpenStack on working days. The laptop held cloud credentials and source-control access. SentinelOne’s comparison is LayerZero’s “Developer1”: the value of the target is whatever the laptop can reach.

Timeline, as published — SentinelOne telemetry, not a reconstructed campaign diary:

When (UTC)WhatStatus
18 Mar 2026FLATROOF and ROOFDECK hashes on diskCONFIRMED (S1)
25–28 MarCursor in daily use; no malicious activity seenCONFIRMED (S1 negative)
29 Mar 05:00cloudshield workspace opened in Cursor; both implants launched with nohup and --type=rendererCONFIRMED
29 Mar 05:00:55C2: SystemUpdatetechnicais / 176.97.114[.]232; iSynchubpage / 45.11.59[.]140; Telegram seconds laterCONFIRMED
29 Mar 05:00:58xattr -rd com.apple.quarantine and chmod +x on iSyncCONFIRMED Gatekeeper bypass
30 Mar–19 AprBeaconing gated on Cursor sessions; quiet when Cursor is offCONFIRMED
13 AprEngineer clones terraform-candidate-repo via GitHub DesktopCONFIRMED clone; after first execution
20 AprNew stripped ROOFDECK (loginwindow) staged from 85.137.56[.]10, C2 grenight[.]com; old binaries deletedCONFIRMED. One day after LayerZero’s public statement. Causal link is ASSESSED, not proven
3 May–1 Junloginwindow beacons to grenight[.]comCONFIRMED
17 Junloginwindow moved to TrashCONFIRMED

The 13 April clone is not the origin story on this host. The implants were already executing two weeks earlier. Treat the Terraform lure as campaign tradecraft, not as the proven vector for this MacBook.

Campaign lure set, recovered from GitHub:

One candidate left a note that they had removed a typosquatted provider. Awareness works. It is not a control.

Why it matters

The interesting fact is not that DPRK operators steal cryptocurrency. It is that the same implants and the same interview packaging landed on an IT-services DevOps endpoint that had no Web3 business.

A developer laptop is a control plane. Terraform, Ansible, AWS, OVH, OpenStack, and source control are how that engineer’s employer — and that employer’s customers — get built. SentinelOne’s conclusion, which we will not inflate: not every foothold becomes a $292 million mint event. The LayerZero / KelpDAO theft remains the high-value case. This one, they assess, was not worth keeping.

That is not comfort. It is a hunting problem. The dwell on this host ran from mid-March into June. Beaconing was gated on an IDE. Persistence looked like Apple: SystemUpdate under com.apple.iTunesCloud, iSync under com.apple.internal.ck, later loginwindow under com.apple.appleaccountd, LaunchAgent with --type=renderer.

ROOFDECK’s C2 discovery uses Nostr relays and an operator profile’s website field as a dead-drop, with Pastebin-style fallback and a pinned TLS certificate minted by mkcert on a QEMU box as user ub. FLATROOF exfiltrates over Telegram. Indicator-based blocking of a single domain does not close that channel.

Do not write an OT event. SentinelOne did not identify industrial-control, SCADA, or physical-process impact. An IT-services firm may have industrial customers. That is UNKNOWN. Inventory whether DevOps laptops can reach those customers. Do not invent a plant incident.

Who / what is affected

AssetWhat to assumeStatus
Apple Silicon macOS DevOps / cloud / FinTech engineering endpointsIn scope for this cluster’s interview lures and these two familiesCONFIRMED toolset; this report is one extra victim
Corporate MacBooks used for external take-home coding testsPolicy gap. SentinelOne recommends against itASSESSED control, not a CVE
Terraform projects whose .terraform.lock.hcl names a registry other than registry.terraform.ioTreat as hostile until proven otherwiseCONFIRMED lure mechanism (LayerZero + recovered repos)
Official Terraform registry modulesCan still be malicious; lockfile domain is necessary, not sufficientCONFIRMED caveat from S1
Cursor / other IDE child processes that are unsigned binaries in $HOME/LibraryHunt classCONFIRMED on this host
Downstream customers of the unnamed Indian IT-services firmUNKNOWN. No customer list. No confirmed follow-onUNKNOWN
Crypto / Web3 engineering orgsStill the historical target set (LayerZero / KelpDAO)CONFIRMED background, not this victim

Technical context

Both implants are ARM64, Rust, built for macOS.

FLATROOF (~/Library/com.apple.iTunesCloud/SystemUpdate, SHA-1 02df07a173ab03b82a4fb6a08973fff8b1467f28): first-stage collection and loader. Commands include shell, upload (Telegram attach), kill, id, stop. A bundled Python harvester takes Chrome, Brave, Firefox, and Safari data, shell history, system_profiler, ps aux, installed apps, and a raw login.keychain-db. On start it strips quarantine from ROOFDECK.

ROOFDECK (~/Library/com.apple.internal.ck/iSync, SHA-1 c491d477dbe0ae04e9aed9dbe237144c03f73ec4; later ~/Library/com.apple.appleaccountd/loginwindow, SHA-1 5728b11d30586bbfc1d8bd12df1c722a06e767a2): second-stage. Config at ~/.config/.repl_history. First-run C2 comes from Nostr profile lookup (api.nostr[.]watch/v1/online plus a hardcoded relay list: relay.damus[.]io, nos[.]lol, nostr[.]mom, relay.snort[.]social, and others). Commands are RSA-signed. The implant reimplements file and directory operations rather than calling the obvious shell — a pattern SentinelOne maps to Lazarus LightlessCan. Persistence: ~/Library/LaunchAgents/ plist, RunAtLoad, --type=renderer. HTTPS tasking path /app_version. IPC pipe /private/tmp/.pipe-airway.

mkcert artifact (hunt this, do not treat as unique to one domain):

ATT&CK mapping (defensive, from observed behavior — not a complete actor playbook): T1566.002 (interview / coding-challenge lure), T1195.002 (malicious Terraform provider), T1059.004 / T1059.006 (shell, Python harvester), T1553.001 (quarantine attribute), T1543.001 (Launch Agent), T1036 (Apple-looking names, --type=renderer), T1555.001 / T1555.003 (keychain, browsers), T1102 (Telegram, Nostr dead-drop), T1071.001 (HTTPS /app_version), T1070.004 (implant deletion on 20 April).

Threat / exploitation status

ClaimGrade
FLATROOF + ROOFDECK on this IT-services MacBook, Mar–Jun 2026CONFIRMED (SentinelOne telemetry)
Same families as LayerZero / KelpDAOCONFIRMED (S1; LayerZero / Mandiant names)
TraderTraitor / Jade Sleet / UNC4899 as the operatorCONFIRMED as SentinelOne’s cluster; RWP confidence moderate pending a second independent public technical match
Terraform lock-file as delivery on this hostUNKNOWN
Terraform lock-file as campaign lureCONFIRMED (recovered repos + LayerZero path)
Current (September) active beaconing on this hostNot in the published telemetry after 1 June; 17 June binary to Trash
Broad IT-services targeting as a new programASSESSED. One extra victim does not prove a sector campaign
Ransomware-KnownNot a CISA field. UNKNOWN
In CISA KEVNo

X discussion of the SentinelOne paper (18–21 September) is amplification, not measurement. RWP used it as discovery only.

What defenders should do

Today, on macOS developer endpoints — especially anyone with cloud or VCS admin:

  1. Hunt the paths and hashes above. Unsigned or ad-hoc-signed Mach-O in $HOME/Library/com.apple.* that is not an Apple-shipped binary is the ticket, not the C2 domain of the week.
  2. Hunt LaunchAgents whose ProgramArguments include --type=renderer and a binary that is not Chromium/Electron.
  3. Hunt IDE telemetry: Cursor, VS Code, JetBrains spawning nohup children under those Library paths. On this host the implants only beaconed while Cursor was running.
  4. Hunt ~/.config/.repl_history as a ROOFDECK config, /private/tmp/.pipe-airway, and $TMPDIR/tmp*.lock.
  5. Pull TLS inspection or certificate inventory for the mkcert ub@ub-Standard-PC-Q35-ICH9-2009 subject. SentinelOne listed related names including grenight[.]com, storage.hubpage[.]cloud, technicais.sytes[.]net, mactroubleshoots[.]pro, heyhay[.]online, galaxy-royal[.]online.
  6. Inventory .terraform.lock.hcl across developer home directories and CI. Flag any provider source host that is not registry.terraform.io. The three typosquats above are sufficient to start; they are not a complete list.
  7. Ask engineers — in a non-punitive channel — whether they ran an external take-home or “interview task” repo on a corporate Mac in 2026. Telemetry will not label a recruiter.
  8. If you find the implants: treat cloud keys, VCS PATs, browser sessions, and the login keychain as burned. Rotate. Do not call the ticket closed on a binary delete; S1 watched the operator delete the first stage themselves on 20 April and keep a stripped successor.

Policy that actually changes the intercept:

Do not publish or replay exploit steps for the Terraform provider, the Nostr dead-drop, or the implants. The hashes, paths, and registry hostnames are enough to hunt.

RWP assessment

Score 8.4. High confidence on the host facts. Moderate confidence on the cluster name. Low confidence that this is a new mass IT-services campaign.

Why this outranked the rest of the window: it is the first Daily Top on this victim expansion; the access class is developer-to-cloud, which is how enterprises actually get run; the primary source is a lab paper with timestamps, hashes, and a honest UNKNOWN on delivery. CISA did not add a KEV row over the weekend — catalog still 2026.09.18 — so there is no federal clock hiding the story.

Runner-up, not selected: Checkmarx’s indexed-btree npm campaign (17 September, BleepingComputer 20 September) is a real supply-chain shift — malware in BTree.prototype.set() instead of install scripts, Checkmarx’s “almost 2 million weekly downloads” claim, packages subsequently pulled. It loses on attribution quality and on “what a CISO does Monday morning” versus a named DPRK toolset on a DevOps Mac. CVE-2026-90817 in REDCap (CNA published 20 September, CVSS 9.8, patch floors 16.0.49 / 17.3.10 / 17.4.4) is unauthenticated RCE through survey passthrough plus data-import, but the CNA requires a valid public survey hash and does not claim exploitation. Vanderbilt / REDCap is a clinical-research surface; we already covered UNC6508’s REDCap espionage as a June backfill. No KEV row. CVE-2026-90822 / 90823 in FatPipe MPVPN (Securifera, 21 September) are unauthenticated root on an EOL image, management interface disabled by default. No in-wild claim. Blackpoint’s ChainScript RAT (21 September) is a new ClickFix / EtherHiding family. Cybercrime, Windows, Polygon resolver — crowded pattern, weaker enterprise control-plane.

We are not scoring “DPRK plus Mac” as automatically 9. The last beacon in the paper is June. The decision this morning is hunt-and-policy, not emergency patching of a KEV appliance.

What we are watching

Sources

Primary: SentinelOne, 18 September 2026. Secondary amplification: The Hacker News, 21 September 2026. KEV negative: CISA catalog 2026.09.18. Runner-up primaries as linked in the header. X used as discovery only.

Sources

  1. SentinelOne — Don’t Call Us, We’ll Call Your APIs
  2. The Hacker News — Jade Sleet Linked to Indian IT Provider Breach
  3. CISA — KEV JSON feed catalog 2026.09.18
  4. CISA — Known Exploited Vulnerabilities Catalog
  5. The Hacker News — ClickFix Lures Deploy ChainScript RAT (Blackpoint APG)
  6. Checkmarx Zero — npm btree malware campaign
  7. CVE — CVE-2026-90817
  8. NVD — CVE-2026-90817
  9. Securifera — One Login, Two RCEs CVE-2026-90822 CVE-2026-90823