Find notable cyber news and cases, enriched with sources, timelines, and signals.

MacOS.Gaslight Rust infostealer-backdoor with Telegram Bot API channel

Malware Activity
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

Researchers identified macOS.Gaslight, a North Korea-linked Rust infostealer-backdoor that can steal Chrome, Brave, Firefox and Safari data, terminal histories, installed-app lists and the macOS login keychain. The sample also offers an interactive shell and routes command traffic through Telegram's Bot API, using encryption and certificate pinning to resist inspection. It embeds 38 fabricated system messages to derail AI-assisted triage before defenders can analyze the implant normally. The blend of credential theft, covert command handling and analysis sabotage increases the risk of unauthorized access and prolonged defender blindness.

Related Happenings

Trojanized Pyrogram forks with hidden Telegram backdoor

Malware Activity
H score14 First: 01.07.2026 00:02 Last: 01.07.2026 00:02 Sources 1

About this happening: Trojanized Pyrogram forks on PyPI now ship a hidden backdoor that gives attackers remote command execution and file access on compromised Telegram bot servers. The mal...

Gaslight macOS implant with Telegram C2 and prompt-injection payload

Malware Activity
H score29 First: 25.06.2026 12:23 Last: 25.06.2026 12:23 Sources 1

About this happening: A previously undocumented macOS implant named Gaslight combines Telegram bot API C2, persistent shell control, and file exfiltration with a built-in prompt-i...

MacOS.Gaslight prompt-injection technique aimed at AI-assisted triage

Technical Analysis
H score23 First: 24.06.2026 17:00 Last: 24.06.2026 17:00 Sources 1

How related: SentinelLabs, the research arm of SentinelOne, said the Rust implant embedded 38 fabricated system messages designed to derail AI-assisted triage.

About this happening: macOS.Gaslight is a Rust-based macOS implant and information stealer assessed with high confidence as the work of North Korea-aligned threat actors. The sample uses ...

SHub Reaper macOS infostealer variant

Malware Activity
H score23 First: 19.05.2026 00:42 Last: 19.05.2026 00:42 Sources 1

About this happening: The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It...

Atomic Stealer macOS Script Editor ClickFix campaign

Campaign
H score42 First: 08.04.2026 21:55 Last: 08.04.2026 21:55 Sources 1

About this happening: A new Atomic Stealer (AMOS) campaign is targeting macOS users through fake Apple-themed cleanup sites, creating a lower-friction path to malware installation and data...

Timeline

  1. 24.06.2026 17:00 2 articles · 21d ago

    SentinelLabs identifies macOS.Gaslight as a North Korea-linked backdoor with prompt injection

    Initial Disclosure

    SentinelLabs disclosed macOS.Gaslight, a Rust macOS backdoor tied with high confidence to North Korean activity, and said the sample embeds 38 fabricated system messages to derail AI-assisted triage. The implant also functions as an infostealer and backdoor, offering an interactive shell, collecting browser data from Chrome, Brave, Firefox and Safari, terminal histories, installed-app lists and the macOS login keychain, and routing command traffic through Telegram's Bot API with encryption and certificate pinning. SentinelLabs also noted runtime Python staging, Telegram bot token scrubbing and an Apple XProtect hit that helped support attribution.

    Show sources