s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-osx.gaslight

📛 Threat Title

Malware family: Gaslight

Category: Gaslight First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.gaslight`. Printable name: Gaslight.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:cyberpress.org

    A new macOS malware family , dubbed macOS. Gaslight has emerged with a novel evasion technique designed specifically to target artificial intelligence. Discovered in early June after an Apple XProtect update, this Rust-based backdoor uses embedded prompt injection to deceive LLM-assisted malware analysis tools.

  • web:itsecuritynewsbox.com

    macOS. Gaslight : DPRK Rust implant for Mac with a prompt injection payload designed to fool AI-based malware analysts. SentinelLabs researchers spotted a Rust-based macOS implant, dubbed macOS. Gaslight , that surfaced in early June after an Apple XProtect update pointed to a VirusTotal sample uploaded on May 22. The binary was undetected by static engines at the time of writing. They named it ...

  • web:latesthackingnews.com

    The Gaslight macOS malware from a North Korean cluster doesn't bypass AI analysis platforms yet, but its 38-message prompt injection cascade makes the direction of travel clear. Here's why this matters beyond the sample itself.

  • web:rishabhyadav.in

    Gaslight is a sophisticated macOS malware that uses prompt injection to disrupt AI-assisted analysis. By understanding its technical aspects, attack vectors, and implications for security professionals, we can develop effective mitigation strategies.

  • web:securityonline.info

    The new macOS Gaslight malware , a North Korean Rust backdoor, targets analysts with LLM prompt injection and steals sensitive keychain data.

  • web:thehackernews.com

    SentinelOne details Gaslight , a Rust-based macOS implant linked to North Korea-aligned actors that uses prompt injection to hinder AI triage.

  • web:www.anavem.com

    A newly identified macOS malware called Gaslight embeds prompt injection strings and fake debug data to deceive AI-powered malware analysis platforms.

  • web:www.sentinelone.com

    However, macOS. Gaslight is noteworthy for its analyst-targeting prompt injection, an attempt to weaponize the LLM-assisted triage pipelines that increasingly sit in the reverse-engineering loop.

  • web:www.techradar.com

    A new piece of malware tries to trick AI-assisted analysis into showing errors.

  • web:zero-day-wire-1.ghost.io

    SentinelOne Labs identified a previously unknown macOS implant called Gaslight that breaks from the usual malware playbook: it targets the analyst's toolset, not just the host. The Rust-based backdoor and information stealer embeds a block of fabricated "system" messages built to fool the large language models now integrated into many reverse-engineering and triage workflows, pushing those ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.