North Korea-Linked Hackers Breach Indian IT Firm: Lessons for Businesses
A North Korea-linked threat actor known as Jade Sleet has been linked to a cyberattack on an Indian IT services company, highlighting how attackers can target developers to gain access to wider business infrastructure.
According to SentinelOne research reported by The Hacker News, attackers compromised the Apple laptop of a DevOps engineer. The activity involved two backdoors, FLATROOF and ROOFDECK, which were discovered on the device. Investigators linked the attack to fake job opportunities and coding tests shared through GitHub.
The case highlights a growing risk for Indian software companies. A developer's device may have access to source code, cloud platforms, deployment systems and other sensitive resources. If that endpoint is compromised, attackers may potentially use those privileges to move deeper into the organisation. The identity of the affected Indian company has not been publicly disclosed.


Businesses should treat developer endpoints as an important part of their security strategy. Employees should verify unexpected job offers and coding assignments, avoid running unfamiliar projects or scripts, and use multi-factor authentication for GitHub and cloud accounts. Organisations should also apply least-privilege access, monitor developer devices, protect endpoints and regularly review access credentials.
For Indian IT and software businesses, protecting developer devices is an important part of reducing endpoint risk. Net Protector Endpoint Security and EDR solutions can support organisations in monitoring and protecting business endpoints against suspicious activity.