Skip to content
DPRK-Linked macOS.Gaslight Implant Targets Analysts with Prompt Injection

DPRK-Linked macOS.Gaslight Implant Targets Analysts with Prompt Injection

First seen 26 Jun 2026, 08:38 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •June 27, 2026 at 08:12 UTC
  • •macOS.Gaslight is a Rust-based implant linked to North Korean cyber operations.
  • •The malware employs prompt injection techniques to deceive AI malware analysts.
  • •It was first identified in early June 2026, with origins traced back to a VirusTotal upload on May 22.

A new Rust-based macOS implant named macOS.Gaslight has been linked to North Korean cyber activities. This malware features a prompt injection payload aimed at misleading AI-based malware analysts. It was first detected in early June 2026, following an Apple XProtect update that flagged a VirusTotal sample uploaded on May 22. The implant is characterized by its hardened Telegram-based command-and-control channel and is ad hoc signed. Researchers from SentinelLabs confirmed its association with DPRK-linked activities, particularly those related to BONZAI and AIRPIPE signatures. The binary remains undetected by static analysis engines, raising concerns about its stealth capabilities. The malware is designed to operate on macOS systems, specifically targeting Mac users. Current assessments indicate a high confidence in its state-sponsored origins.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 96d ago How this analysis works

Timeline

2026-05-22
VirusTotal sample uploaded
A sample of macOS.Gaslight was uploaded to VirusTotal, marking its first known appearance.
Securityaffairs.Co
2026-06-01
Detection by Apple XProtect
An update from Apple XProtect flagged the macOS.Gaslight implant, indicating its malicious nature.
Securityaffairs.Co
2026-06-25
Gbhackers report published
Gbhackers published an analysis confirming the link between macOS.Gaslight and DPRK activities.
Gbhackers
2026-06-26
Securityaffairs report published
Securityaffairs detailed the capabilities of macOS.Gaslight and its prompt injection payload.
Securityaffairs.Co

More articles in this cluster (2)

Following this threat?

Track MacOS.Gaslight in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed