logo

New macOS Gaslight Malware Targets AI Analysis Tools

ID: acc86bd3-0f3b-57b6-a3e1-24e36bb630b2

STIX ID: report--acc86bd3-0f3b-57b6-a3e1-24e36bb630b2

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-06-25

Date Updated: 2026-07-02

...
...

A newly discovered macOS malware named "Gaslight," attributed with high confidence to North Korean actors, uses an innovative prompt-injection technique—embedding dozens of fake system messages in its Rust binary—to confuse AI-assisted malware analysis tools. The malware also exfiltrates data, provides remote access to attackers via encrypted Telegram Bot API communications, and has been detected by Apple's XProtect, indicating active deployment and a notable evolution in evasion tactics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.