Securityaffairs.Co DPRK-Linked macOS.Gaslight Implant Targets Analysts with Prompt Injection
Article Content
- •macOS.Gaslight is a Rust-based implant linked to North Korean cyber operations.
- •The malware employs prompt injection techniques to deceive AI malware analysts.
- •It was first identified in early June 2026, with origins traced back to a VirusTotal upload on May 22.
A new Rust-based macOS implant named macOS.Gaslight has been linked to North Korean cyber activities. This malware features a prompt injection payload aimed at misleading AI-based malware analysts. It was first detected in early June 2026, following an Apple XProtect update that flagged a VirusTotal sample uploaded on May 22. The implant is characterized by its hardened Telegram-based command-and-control channel and is ad hoc signed. Researchers from SentinelLabs confirmed its association with DPRK-linked activities, particularly those related to BONZAI and AIRPIPE signatures. The binary remains undetected by static analysis engines, raising concerns about its stealth capabilities. The malware is designed to operate on macOS systems, specifically targeting Mac users. Current assessments indicate a high confidence in its state-sponsored origins.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track MacOS.Gaslight in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…