SentinelLabs has linked a second victim to the same macOS backdoors used in the April LayerZero breach, an IT services provider in India that has no cryptocurrency ties. The finding suggests the tools are not limited to crypto targets.
The backdoors are named FLATROOF, tracked as macOS.Gaslight, and ROOFDECK. Both are ARM64 macOS implants written in Rust, and both were first observed in the LayerZero attack. The victim endpoint was an Apple Silicon MacBook belonging to a DevOps engineer, a machine that held cloud credentials and source control access.
The attackers behind the campaign are known as TraderTraitor, a financially motivated subgroup of North Korea's Lazarus group that also goes by UNC4899, PUKCHONG and Jade Sleet. The April LayerZero breach stole USD 292 million from KelpDAO, a DeFi protocol supporting Ethereum restaking, after attackers faked a crypto minting event and hit validation servers with a DDoS. LayerZero enables cryptocurrency exchange across blockchains.
According to the report, the campaign uses fake job interview lures in the style of the Contagious Interview approach, aimed at people working in DevOps or crypto and FinTech engineering. Weaponized GitHub repositories include Northwind-IAC, novacart-interview and terraform-candidate-repo, referencing companies called Northwind and Novacart. It is unclear whether those companies are fabricated or real, and one Northwind example describes an ecommerce company that is launching soon.
The repositories carry a weaponized .terraform.lock.hcl file whose malicious custom provider points to an attacker-controlled domain. Three malicious provider domains were identified across the repositories: registry.hashicorp-aws[.]com, registry.hashicorp-aws[.]io and registry.hashicorp-terraform[.]io. Running terraform init with the weaponized lockfile downloads and executes the malicious provider. One candidate removed the typosquatted provider and left a note.
In the LayerZero case, an employee installed a weaponized interview project on a workstation, and the backdoors went on to collect API keys and escalate privileges before the attackers expanded into the victim's AWS and Google Cloud Platform environments. On the newly identified machine, both backdoors were on disk as far back as March 18, though the delivery method is unproven. They stayed dormant until March 29, when beaconing began. Cursor launched both implants that day, seconds after the workspace opened.
FLATROOF was deployed as SystemUpdate in ~/Library/com.apple.iTunesCloud/. It removes the quarantine attribute and sets the executable bit on ROOFDECK, which then runs with no signature check and no user prompt. FLATROOF appears intended for initial data collection and secondary payloads. Beaconing is gated on Cursor sessions and goes quiet when Cursor is off.
The developer cloned terraform-candidate-repo through GitHub Desktop on April 13. FLATROOF re-armed ROOFDECK on April 14 at 18:25. On April 20, the day after LayerZero issued a statement, ROOFDECK staged a third-stage loginwindow, which then deleted both original implants at 13:15 and beaconed to grenight[.]com until June 1. Other command-and-control domains named in the report include technicais at 176[.]97.114.232 and hubpage at 45[.]11.59.140, with a staging IP at 85[.]137.56.10. SentinelLabs published a detailed FLATROOF analysis in June 2026.













