Two Rust backdoors written for Apple Silicon Macs have been tied to a North Korean intrusion at an India-based IT services firm, according to SentinelOne.
Nobody named the vendor. The trail instead runs through a DevOps engineer’s MacBook, where the implants sat dormant for eleven days before Cursor launched them seconds after a project workspace opened on March 29, 2026.
The two families are FLATROOF, also called Gaslight, and ROOFDECK. SentinelOne had seen both before, during the March-April 2026 raid on KelpDAO’s LayerZero bridge. The actor behind them answers to several names, among them Jade Sleet, Slow Pisces, TraderTraitor and UNC4899, and it mainly hunts cryptocurrency firms by going after their suppliers.
Where the trap is hidden
Applications arrive as coding projects. The repositories look like infrastructure work for whichever company the operators are impersonating, and the payload hides in a Terraform dependency lock file. Its entries point at domains such as registry.hashicorp-aws[.]com, so one terraform init call pulls down modules the operators control. Treat lock files like executable code, because that is what they are.
The implants differ in plumbing. FLATROOF talks to Telegram and harvests browser data from Chrome, Brave, Firefox and Safari alongside terminal history, installed applications and login.keychain-db. ROOFDECK spreads its command channel across the Nostr protocol, checks signed commands against an embedded key, and persists through Launch Agents.
