New macOS Gaslight Malware Targets AI Analysis Tools
ID: acc86bd3-0f3b-57b6-a3e1-24e36bb630b2
STIX ID: report--acc86bd3-0f3b-57b6-a3e1-24e36bb630b2
Feed Name: ThreatCluster
A newly discovered macOS malware named "Gaslight," attributed with high confidence to North Korean actors, uses an innovative prompt-injection technique—embedding dozens of fake system messages in its Rust binary—to confuse AI-assisted malware analysis tools. The malware also exfiltrates data, provides remote access to attackers via encrypted Telegram Bot API communications, and has been detected by Apple's XProtect, indicating active deployment and a notable evolution in evasion tactics.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
