logo

Rust macOS Backdoor Uses Interactive Shell and Telegram File Uploads for Data Theft

ID: 61d9b63c-7e4c-522f-a9f2-2984845203a7

STIX ID: report--61d9b63c-7e4c-522f-a9f2-2984845203a7

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-06-25

Date Updated: 2026-06-25

Author: Tushar Subhra Dutta

...
...

A newly discovered Rust-based macOS backdoor named macOS.Gaslight steals browser credentials, terminal histories, and the macOS login keychain, bundles collected data into a zip, and exfiltrates it via the Telegram Bot API; the implant uses AES-GCM, certificate pinning, proxy handling, a LaunchAgent for persistence, and embeds 38 fabricated messages designed to manipulate AI-based analysis pipelines. SentinelOne links the sample to DPRK-associated activity, and the report provides multiple IoCs (SHA-256 hashes, an embedded signing identifier, a LaunchAgent label, and a Python payload hash) along with mitigation advice to treat unknown files as adversarial input before exposing them to AI tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.