TF-MAL-osx.gaslight
📛 Threat Title
Malware family: Gaslight
Description
ThreatFox malware family `osx.gaslight`. Printable name: Gaslight.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cyberpress.org
A new macOS malware family , dubbed macOS. Gaslight has emerged with a novel evasion technique designed specifically to target artificial intelligence. Discovered in early June after an Apple XProtect update, this Rust-based backdoor uses embedded prompt injection to deceive LLM-assisted malware analysis tools.
-
web:itsecuritynewsbox.com
macOS. Gaslight : DPRK Rust implant for Mac with a prompt injection payload designed to fool AI-based malware analysts. SentinelLabs researchers spotted a Rust-based macOS implant, dubbed macOS. Gaslight , that surfaced in early June after an Apple XProtect update pointed to a VirusTotal sample uploaded on May 22. The binary was undetected by static engines at the time of writing. They named it ...
-
web:latesthackingnews.com
The Gaslight macOS malware from a North Korean cluster doesn't bypass AI analysis platforms yet, but its 38-message prompt injection cascade makes the direction of travel clear. Here's why this matters beyond the sample itself.
-
web:rishabhyadav.in
Gaslight is a sophisticated macOS malware that uses prompt injection to disrupt AI-assisted analysis. By understanding its technical aspects, attack vectors, and implications for security professionals, we can develop effective mitigation strategies.
-
web:securityonline.info
The new macOS Gaslight malware , a North Korean Rust backdoor, targets analysts with LLM prompt injection and steals sensitive keychain data.
-
web:thehackernews.com
SentinelOne details Gaslight , a Rust-based macOS implant linked to North Korea-aligned actors that uses prompt injection to hinder AI triage.
-
web:www.anavem.com
A newly identified macOS malware called Gaslight embeds prompt injection strings and fake debug data to deceive AI-powered malware analysis platforms.
-
web:www.sentinelone.com
However, macOS. Gaslight is noteworthy for its analyst-targeting prompt injection, an attempt to weaponize the LLM-assisted triage pipelines that increasingly sit in the reverse-engineering loop.
-
web:www.techradar.com
A new piece of malware tries to trick AI-assisted analysis into showing errors.
-
web:zero-day-wire-1.ghost.io
SentinelOne Labs identified a previously unknown macOS implant called Gaslight that breaks from the usual malware playbook: it targets the analyst's toolset, not just the host. The Rust-based backdoor and information stealer embeds a block of fabricated "system" messages built to fool the large language models now integrated into many reverse-engineering and triage workflows, pushing those ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.