Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Gaslight macOS Malware Targets AI Analysis with Prompt Injection

Gaslight macOS Malware Targets AI Analysis with Prompt Injection

Posted on June 25, 2026 By CWS

A newly identified macOS malware, termed Gaslight, has emerged with the capability to hinder AI-assisted malware analysis. Developed using Rust, this implant and information stealer employs a prompt injection payload to deceive AI tools used by malware analysts, leading them to prematurely halt or refuse investigation.

The Gaslight malware is believed to originate from North Korea-aligned cyber actors, as reported by SentinelOne researcher Phil Stokes. A defining feature of this malware is its deployment of fabricated system-failure messages designed to confuse large language model (LLM)-based triage agents, impacting their judgment rather than the sandbox environment in which they operate.

Advanced Command-and-Control Features

Integral to Gaslight’s architecture is a command-and-control (C2) channel utilizing a Telegram bot API. This allows the malware operator to execute commands through an interactive shell and receive execution results. In cases where two instances of the same bot token attempt simultaneous polling, an automatic “Conflict” response ends the session for the second instance.

The shell offers six core commands, facilitating a persistent presence within the infected system. These commands include:

  • help: Displays available commands
  • id: Identifies the implant
  • shell: Executes shell commands
  • kill: Ends a process by its PID
  • upload: Extracts files using Telegram’s “attach://”
  • stop: Halts implant execution

Moreover, evidence suggests a seventh command, “focus,” though its specific function remains unclear. Gaslight gains persistence by employing a LaunchAgent with the label “com.apple.system.services.activity” in its configuration file.

Comprehensive Data Collection

The malware embeds a 6.6 KB Base64-encoded Python script to systematically gather information, including Terminal command history, installed applications, active processes, system profiles, and browser data from Chrome, Brave, Firefox, and Safari. This data is then compressed and transmitted via Telegram.

Deployment of the Python script occurs through a separate 2 KB Base64-encoded bash installer that incorporates a cpython-3.10.18 interpreter. The script’s use of emojis and detailed comment headers suggests generation by a large language model (LLM).

Evading Detection with AI Deception

Gaslight’s unique approach to evading AI-based detection involves runtime-provided bot token and configuration details, avoiding hard-coded information within the malware sample. This self-redaction feature prevents log or crash artifact capture from revealing the Telegram bot token.

Furthermore, Gaslight includes a Markdown-fenced block with 38 fabricated “system” messages aimed at misleading security agents. These messages falsely report issues like token expiry, memory overflows, disk space depletion, injection vulnerabilities, and static-analysis concerns, effectively weaponizing AI-driven triage processes in reverse-engineering loops.

This sophisticated strategy underscores the evolving nature of malware tactics and the need for robust cybersecurity measures.

The Hacker News Tags:AI security, cybersecurity threats, Gaslight malware, information stealer, macOS security, malware analysis, North Korea cyber attack, prompt injection, SentinelOne, Telegram bot

Post navigation

Previous Post: WhatsApp Introduces New Security Alerts for Unknown Numbers
Next Post: GitLab Releases Updates for Critical Security Flaws

Related Posts

Chinese Hackers Target Azerbaijani Energy Firm via Microsoft Exchange Chinese Hackers Target Azerbaijani Energy Firm via Microsoft Exchange The Hacker News
Critical SmartConsole Vulnerability Patched by Check Point Critical SmartConsole Vulnerability Patched by Check Point The Hacker News
Smishing Triad Linked to 194,000 Malicious Domains in Global Phishing Operation Smishing Triad Linked to 194,000 Malicious Domains in Global Phishing Operation The Hacker News
Rust Adoption Drives Android Memory Safety Bugs Below 20% for First Time Rust Adoption Drives Android Memory Safety Bugs Below 20% for First Time The Hacker News
Malicious Go Module Poses as SSH Brute-Force Tool, Steals Credentials via Telegram Bot Malicious Go Module Poses as SSH Brute-Force Tool, Steals Credentials via Telegram Bot The Hacker News
North Korean Hackers Target Axios, Chrome Exploits, Fortinet Breaches North Korean Hackers Target Axios, Chrome Exploits, Fortinet Breaches The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CEVA Logistics Breach Exposes Steam Hardware Buyers
  • Stealthium Enhances Security for AI Accelerators and Neo-Clouds
  • North Korean Hackers Utilize AI for Enhanced Phishing Tactics
  • Ransomware Tactics: Disabling Security Before Encryption
  • Ghostjacking Threatens AI Security Through Trusted Tools

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CEVA Logistics Breach Exposes Steam Hardware Buyers
  • Stealthium Enhances Security for AI Accelerators and Neo-Clouds
  • North Korean Hackers Utilize AI for Enhanced Phishing Tactics
  • Ransomware Tactics: Disabling Security Before Encryption
  • Ghostjacking Threatens AI Security Through Trusted Tools

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark