GajIPS - IPS Signature Update — GS TROJAN: TraderTraitor / Jade Sleet FLATROOF & ROOFDECK macOS backdoor delivery and C2
Severity: HIGH · Priority: P2 — targeted nation-state supply-chain intrusion, escalate on hit
These rules detect network activity from a supply-chain campaign by TraderTraitor — also known as Jade Sleet, PUKCHONG, Slow Pisces, and UNC4899 — a North Korean state-sponsored group and financially-motivated subgroup of Lazarus, responsible for the April 2026 KelpDAO/LayerZero theft ($292 million) and the 2025 Bybit compromise ($1.5 billion). The campaign is directly relevant to Indian organisations: Researchers confirmed the most recently identified victim is an Indian IT services provider with no cryptocurrency ties, showing the group's targeting has expanded beyond the crypto sector. The attack uses a weaponised Terraform coding project as its lure — a fake job-interview assignment whose lockfile secretly points Terraform to attacker-controlled registries impersonating HashiCorp domains. Running a standard terraform init command causes Terraform to download and execute the attacker's code, deploying two Rust-based macOS backdoors: FLATROOF for persistence and credential harvesting, and ROOFDECK for ongoing remote control and data exfiltration. ROOFDECK discovers its command servers through posts on public Nostr relay servers, making infrastructure rotation easy for the attackers.