DPRK-Linked macOS.Gaslight Implant Targets Analysts with Prompt Injection

DPRK-Linked macOS.Gaslight Implant Targets Analysts with Prompt Injection

First seen 26 Jun 2026, 08:38 UTC GbhackersSecurityaffairs.Co 75% similarity 69.6
Share:

Article Content

Browse articles
ThreatCluster

A new Rust-based macOS implant named macOS.Gaslight has been linked to North Korean cyber activities. This malware features a prompt injection payload aimed at misleading AI-based malware analysts. It was first detected in early June 2026, following an Apple XProtect update that flagged a VirusTotal sample uploaded on May 22. The implant is characterized by its hardened Telegram-based command-and-control channel and is ad hoc signed. Researchers from SentinelLabs confirmed its association with DPRK-linked activities, particularly those related to BONZAI and AIRPIPE signatures. The binary remains undetected by static analysis engines, raising concerns about its stealth capabilities. The malware is designed to operate on macOS systems, specifically targeting Mac users. Current assessments indicate a high confidence in its state-sponsored origins.

Key Points: • macOS.Gaslight is a Rust-based implant linked to North Korean cyber operations. • The malware employs prompt injection techniques to deceive AI malware analysts. • It was first identified in early June 2026, with origins traced back to a VirusTotal upload on May 22.

ThreatCluster AI

Timeline

2026-05-22
VirusTotal sample uploaded
A sample of macOS.Gaslight was uploaded to VirusTotal, marking its first known appearance.
Securityaffairs.Co
2026-06-01
Detection by Apple XProtect
An update from Apple XProtect flagged the macOS.Gaslight implant, indicating its malicious nature.
Securityaffairs.Co
2026-06-25
Gbhackers report published
Gbhackers published an analysis confirming the link between macOS.Gaslight and DPRK activities.
Gbhackers
2026-06-26
Securityaffairs report published
Securityaffairs detailed the capabilities of macOS.Gaslight and its prompt injection payload.
Securityaffairs.Co

Community

Browse all →