New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis
ID: f1c2b023-e261-5b47-be91-5840d886b367
STIX ID: report--f1c2b023-e261-5b47-be91-5840d886b367
Feed Name: The Hacker News
Threat Score
Gaslight is a newly documented Rust-based macOS implant and infostealer that uses a Telegram bot for command-and-control, embeds a Base64-encoded Python data-stealer deployed via a standalone CPython drop, and achieves persistence via a LaunchAgent. Notably, it contains a Markdown-fenced cascade of fabricated system messages designed as a prompt-injection to disrupt LLM-assisted analysis workflows; researchers attribute it with high confidence to North Korea-aligned threat actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
