CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 602

As cited

Copy frozen at (site build).

threat intel

macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox

SentinelLabs has identified macOS.Gaslight, a Rust-based macOS implant attributed to North Korean threat actors that uses Telegram Bot API for command-and-control communications. The implant's notable capability is an embedded payload of fabricated system messages designed to deceive LLM-assisted security analysis tools into aborting their analysis. Communications are hardened with AES-GCM encryption, certificate pinning, and the implant self-redacts sensitive tokens from its runtime output.

Why it matters: macOS users and security teams running LLM-assisted malware analysis pipelines face a novel evasion technique; defenders need to validate analysis results independently and monitor for DPRK-aligned macOS activity using Apple's XProtect signatures BONZAI and AIRPIPE.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox

SentinelLABS analyzed macOS.Gaslight, a Rust-written backdoor that injects fabricated system messages into artificial intelligence (AI) triage pipelines to prevent analysis rather than attacking the sandbox directly. The implant communicates via Telegram Bot application programming interface (API) polling loops with AES-GCM encryption and certificate-pinned transport layer security (TLS), and self-redacts its bot token from runtime logs. The malware is attributed to North Korean threat actors based on overlap with the BONZAI signature family detected by Apple's XProtect.

Why it matters: macOS security teams need to understand that adversaries now target AI-assisted analysis workflows themselves; this implant uses prompt injection to evade automated threat triage, requiring human review of suspicious binaries even when ML-based detection flags them.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox

SentinelLABS analyzed macOS.Gaslight, a Rust-written backdoor that injects fabricated system messages into artificial intelligence (AI) triage pipelines to prevent analysis rather than attacking the sandbox directly. The implant communicates via Telegram Bot application programming interface (API) polling loops with AES-GCM encryption and certificate-pinned transport layer security (TLS), and self-redacts its bot token from runtime logs. The malware is attributed to North Korean threat actors based on overlap with the BONZAI signature family detected by Apple's XProtect.

Why it matters: macOS security teams need to understand that adversaries now target AI-assisted analysis workflows themselves; this implant uses prompt injection to evade automated threat triage, requiring human review of suspicious binaries even when ML-based detection flags them.

VendorsApple
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary