logo

macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox

Threat Score
88/100

Date Published: 2026-06-23

Date Updated: 2026-07-27

Author: Phil Stokes

...
...

SentinelLABS analyzed a Rust macOS implant dubbed macOS.Gaslight that provides an interactive shell, steals browser and keychain data via a staged Python stealer, persists via a LaunchAgent, and communicates with its operator over a hardened Telegram Bot API channel (AES-GCM over certificate-pinned TLS). The sample embeds a 3.5 KB prompt-injection payload of 38 fabricated system messages designed to disrupt LLM-assisted triage pipelines and is assessed as part of DPRK-aligned macOS activity; IOCs (hashes, LaunchAgent label, ad-hoc signing identifier) are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.