As cited
Copy frozen at (site build).
threat intel
macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox
SentinelLabs has identified macOS.Gaslight, a Rust-based macOS implant attributed to North Korean threat actors that uses Telegram Bot API for command-and-control communications. The implant's notable capability is an embedded payload of fabricated system messages designed to deceive LLM-assisted security analysis tools into aborting their analysis. Communications are hardened with AES-GCM encryption, certificate pinning, and the implant self-redacts sensitive tokens from its runtime output.
Why it matters: macOS users and security teams running LLM-assisted malware analysis pipelines face a novel evasion technique; defenders need to validate analysis results independently and monitor for DPRK-aligned macOS activity using Apple's XProtect signatures BONZAI and AIRPIPE.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox
SentinelLABS analyzed macOS.Gaslight, a Rust-written backdoor that injects fabricated system messages into artificial intelligence (AI) triage pipelines to prevent analysis rather than attacking the sandbox directly. The implant communicates via Telegram Bot application programming interface (API) polling loops with AES-GCM encryption and certificate-pinned transport layer security (TLS), and self-redacts its bot token from runtime logs. The malware is attributed to North Korean threat actors based on overlap with the BONZAI signature family detected by Apple's XProtect.
Why it matters: macOS security teams need to understand that adversaries now target AI-assisted analysis workflows themselves; this implant uses prompt injection to evade automated threat triage, requiring human review of suspicious binaries even when ML-based detection flags them.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox
SentinelLABS analyzed macOS.Gaslight, a Rust-written backdoor that injects fabricated system messages into artificial intelligence (AI) triage pipelines to prevent analysis rather than attacking the sandbox directly. The implant communicates via Telegram Bot application programming interface (API) polling loops with AES-GCM encryption and certificate-pinned transport layer security (TLS), and self-redacts its bot token from runtime logs. The malware is attributed to North Korean threat actors based on overlap with the BONZAI signature family detected by Apple's XProtect.
Why it matters: macOS security teams need to understand that adversaries now target AI-assisted analysis workflows themselves; this implant uses prompt injection to evade automated threat triage, requiring human review of suspicious binaries even when ML-based detection flags them.
- Source published
- First seen by Cybersecurity Tracker