Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

A massive cybersecurity breach has been linked to a previously unknown vulnerability in an Indian IT provider’s software, allowing hackers to gain unauthorized access to sensitive systems and data. The breach is believed to have occurred using two backdoors, FLATROOF and ROOFDECK, which exploit weaknesses in the company’s codebase.

The affected IT provider, whose name has not been disclosed, supplies services to numerous government agencies and private sector organizations across India. As a result, thousands of individuals and businesses may be at risk due to compromised data security. The breach is thought to have occurred through a software development vulnerability, which was exploited by hackers to introduce the FLATROOF and ROOFDECK backdoors.

To understand how this works, consider what privilege escalation entails. When an attacker has access to one system or network within an organization, they can often find ways to “jump” to other systems that have higher levels of clearance or access. This is known as cross-domain privilege escalation. In this case, the hackers appear to have exploited a software vulnerability to gain elevated privileges and then used those privileges to install the backdoors, FLATROOF and ROOFDECK.

The presence of these backdoors allows the attackers to maintain persistent access to affected systems, enabling them to carry out further malicious activities, such as data theft or ransomware attacks. This not only compromises sensitive information but also poses a significant risk to the stability and security of the organizations involved.

What makes this breach particularly concerning is its potential for widespread impact. The Indian IT provider’s services are used by numerous entities, including government agencies and private sector companies. As such, the compromised systems could be leveraged to access confidential data or disrupt operations on a large scale. This serves as a stark reminder of the importance of robust cybersecurity measures in software development, not just for protecting against external threats but also preventing insider attacks.

The incident highlights the need for organizations to implement stringent security protocols and regular vulnerability assessments to prevent similar breaches from occurring in the future. Additionally, developers must prioritize code quality and rigorously test their products for vulnerabilities before deployment. By taking proactive measures, businesses can reduce their exposure to cyber risks and ensure the integrity of their systems and data.


Source: The Hacker News — 2026-09-21