Find notable cyber news and cases, enriched with sources, timelines, and signals.

MacOS.Gaslight prompt-injection technique aimed at AI-assisted triage

Technical Analysis
First reported
Last updated
Happening score
H score 23
3 unique sources, 3 articles

Summary

Hide ▲

macOS.Gaslight is a Rust-based macOS implant and information stealer assessed with high confidence as the work of North Korea-aligned threat actors. The sample uses Telegram Bot API C2 and embeds prompt injection content, including 38 fabricated system messages inside a Markdown-fenced block, to try to make AI-assisted malware triage abort, truncate, or refuse analysis. It also remains a working backdoor/infostealer, collecting data from Chrome, Brave, Firefox, Safari, terminal histories, installed apps, and the macOS login keychain. SentinelOne reported that the deceptive text includes bogus token-expiry, out-of-memory, disk-exhaustion, and repeated-operation errors, plus false warnings about injection and static-analysis issues. The implant can open an interactive shell, use a LaunchAgent for persistence, and upload collected data through Telegram, with operator settings supplied at runtime and the bot token redacted from its own output. The activity directly targets LLM-assisted reverse-engineering workflows by trying to make analysis tools doubt the sample and stop processing it.

Related Happenings

Trojanized Pyrogram forks with hidden Telegram backdoor

Malware Activity
H score14 First: 01.07.2026 00:02 Last: 01.07.2026 00:02 Sources 1

About this happening: Trojanized Pyrogram forks on PyPI now ship a hidden backdoor that gives attackers remote command execution and file access on compromised Telegram bot servers. The mal...

MacOS.Gaslight AI-analysis evasion malware

Malware Activity
H score22 First: 25.06.2026 19:23 Last: 25.06.2026 19:23 Sources 1

How related: A newly discovered macOS malware dubbed "Gaslight" is designed to confuse AI-assisted malware analysis tools by hiding prompt injection strings and fake debugging data within the executable.

About this happening: The macOS.Gaslight malware family now embeds prompt injection strings and fake system-failure messages to confuse AI-assisted malware analysis tools, risking aborted o...

Kandji security patch release for CVE-2026-39118

Security Patch Release
H score17 First: 25.06.2026 14:00 Last: 25.06.2026 14:00 Sources 1

About this happening: Kandji fixed its MDM agent on macOS and assigned CVE-2026-39118 after validation showed a trust issue that could let a standard user disable enterprise security contro...

Gaslight macOS implant with Telegram C2 and prompt-injection payload

Malware Activity
H score29 First: 25.06.2026 12:23 Last: 25.06.2026 12:23 Sources 1

How related: A previously undocumented Rust-based macOS implant and information stealer has been found to embed a prompt injection payload designed to trick a malware analyst's artificial intelligence (AI) tools and trick it into aborting or refusing an analysis of the artifact.

About this happening: A previously undocumented macOS implant named Gaslight combines Telegram bot API C2, persistent shell control, and file exfiltration with a built-in prompt-i...

MacOS.Gaslight Rust infostealer-backdoor with Telegram Bot API channel

Malware Activity
H score30 First: 24.06.2026 17:00 Last: 24.06.2026 17:00 Sources 1

How related: Behind the injection sat a full infostealer and backdoor. The researchers said the implant offered an operator an interactive shell and was built to grab browser data from Chrome, Brave, Firefox and Safari, terminal histories, installed-app lists and a copy of the macOS login keychain.

About this happening: Researchers identified macOS.Gaslight, a North Korea-linked Rust infostealer-backdoor that can steal Chrome, Brave, Firefox and Safari data, terminal histories, in...

Timeline

  1. 24.06.2026 17:00 4 articles · 21d ago

    SentinelLabs identifies macOS.Gaslight prompt injection targeting AI-assisted triage

    Technical Analysis Update

    SentinelLabs identified a North Korea-linked macOS backdoor tracked as macOS.Gaslight that embeds 38 fabricated system messages inside a Markdown-fenced block to confuse AI-assisted triage and derail malware analysts' tools. The Rust implant also functions as an infostealer/backdoor, with an interactive shell, browser data collection from Chrome, Brave, Firefox and Safari, terminal history access, installed-app list collection, and a copy of the macOS login keychain, while its command channel uses Telegram's Bot API with encryption and certificate pinning.

    Show sources