logo

DPRK-Linked macOS Implant Uses LaunchAgent Persistence and Python Stealer Module

ID: 1c7a13f7-62bd-5c99-b9d9-6b854465e246

STIX ID: report--1c7a13f7-62bd-5c99-b9d9-6b854465e246

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-06-25

Date Updated: 2026-06-25

Author: Mayura Kathir

...
...

macOS.Gaslight is a Rust-implemented macOS implant and infostealer attributed to DPRK-linked operators (BONZAI/AIRPIPE). The sample uses a hardened Telegram Bot API C2 with per-message AES-GCM encryption and certificate pinning, self-redacts credentials at runtime, persists via a LaunchAgent, and deploys a base64-encoded Python stealer and bash installer to harvest browsers, terminal histories, and login.keychain-db. Notably, it contains a 3.5 KB prompt-injection payload designed to manipulate LLM-assisted analyst tooling; the report includes multiple IOCs (file hashes, signing identifier, LaunchAgent label) for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.