logo

New macOS Malware 'Gaslight' Uses AI Confusion Tactics

ID: 21c3a0d3-d38d-590d-9bff-5a9610ada05f

STIX ID: report--21c3a0d3-d38d-590d-9bff-5a9610ada05f

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-06-25

Date Updated: 2026-06-26

...
...

Gaslight is a newly identified macOS malware attributed to North Korean actors that uses an unusual evasion technique—embedding 38 fabricated system messages inside its Rust binary to mislead AI-assisted malware analysis—while providing backdoor and information-stealing functionality (targeting browsers and the macOS keychain) and communicating via Telegram Bot API for encrypted command-and-control.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.