Close Menu
    What's Hot

    Top developers are shifting from chatbots to physical AI. Here’s why

    Opinion | The Supreme Court’s TPS Decision Is a Slap in the Face to Lawful Immigrants

    Inside the C.D.C.’s Mad Scramble to Meet Kennedy’s Demands

    Facebook X (Twitter) Instagram
    Trending
    • Top developers are shifting from chatbots to physical AI. Here’s why
    • Opinion | The Supreme Court’s TPS Decision Is a Slap in the Face to Lawful Immigrants
    • Inside the C.D.C.’s Mad Scramble to Meet Kennedy’s Demands
    • Devastating Earthquakes Will Test Venezuela’s Newfound Alliance With U.S.
    • IBM Unveils New Method to Make Smaller Computer Chip Parts
    • UK arm of Crédit Agricole to pay £32mn to clients of WealthTek
    • New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis
    • The Ebola Outbreak’s Central Mystery: Where Did This Virus Come From?
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis

    adminBy adminJune 25, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJun 25, 2026AI Security / Malware

    New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis

    A previously undocumented Rust-based macOS implant and information stealer has been found to embed a prompt injection payload designed to trick a malware analyst’s artificial intelligence (AI) tools and trick it into aborting or refusing an analysis of the artifact.

    The malware has been codenamed Gaslight owing to this deceptive behavior. It’s been assessed with high confidence that the tool is the work of North Korea-aligned threat actors.

    “Its most notable feature is an embedded cascade of fabricated system-failure messages, designed to make an LLM-assisted triage agent doubt its own session,” SentinelOne researcher Phil Stokes said in a technical report. “It attacks the agent’s perception, rather than the sandbox it runs in.”

    Central to the malware’s architecture is a Telegram bot API based command-and-control (C2) channel that enters into a polling loop, allowing the operator to issue instructions over an interactive shell and return the results of the execution. In the event two instances of the same bot token poll simultaneously, a “Conflict” response is issued, causing the second copy to terminate.

    Cybersecurity

    The shell supports six main commands, granting a persistent foothold over the infected host –

    • help, to show command help
    • id, to identify the implant to the operator
    • shell, to execute a shell command via execvp
    • kill, to terminate a target process by PID
    • upload, to exfiltrate a file via Telegram’s “attach://” mechanism
    • stop, to halt the execution of the implant

    SentinelOne said it identified signs suggesting the presence of a seventh command named “focus,” although its functionality remains undetermined at this stage. To achieve persistence, Gaslight makes use of a LaunchAgent that uses the label “com.apple.system.services.activity” in its .plist file.

    Also embedded within the malware is a 6.6 KB Base64-encoded Python script that functions as an information gathering suite responsible for harvesting Terminal command histories, installed application listings, snapshots of running processes, system hardware and software profile, macOS Keychain database, and data from Chrome, Brave, Firefox, and Safari web browsers. The collected data is subsequently compressed into a ZIP archive (“temp/collected_data.zip”) and uploaded via Telegram.

    The Python stealer, for its part, is deployed by means of a separate 2 KB Base64-encoded bash installer that drops a cpython-3.10.18 interpreter from the “astral-sh/python-build-standalone” project. The presence of emojis and extensive comment headers indicates that it was likely generated using a large language model (LLM).

    Cybersecurity

    What’s notable about Gaslight is that details related to the bot token, the chat ID (tg_room_id), and the rest of the operator configuration are not hard-coded into the sample, but rather supplied at runtime. “The implant self-redacts its Telegram bot token in its own runtime output, denying it to anyone who captures logs or crash artifacts,” Stokes added.

    On top of that, the malware attempts to evade an AI-based detection by incorporating a Markdown-fenced block containing 38 fabricated “system” messages designed to trick a security agent into aborting, truncating, or refusing analysis.

    “The scaffold contains fake system messages about token expiry, out-of-memory kills, disk exhaustion, and repeated operation failures. It also plants bogus warnings about injection vulnerabilities and static-analysis flags,” SentinelOne said, calling it an “attempt to weaponize the LLM-assisted triage pipelines that increasingly sit in the reverse-engineering loop.”

    AIAssisted analysis Disrupt Gaslight Injection macOS Malware prompt
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleThe Ebola Outbreak’s Central Mystery: Where Did This Virus Come From?
    Next Article UK arm of Crédit Agricole to pay £32mn to clients of WealthTek
    admin
    • Website

    Related Posts

    Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability

    June 25, 2026

    Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories

    June 25, 2026

    Richard Bejtlich on the Case for NDR

    June 25, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Top developers are shifting from chatbots to physical AI. Here’s why

    Opinion | The Supreme Court’s TPS Decision Is a Slap in the Face to Lawful Immigrants

    Inside the C.D.C.’s Mad Scramble to Meet Kennedy’s Demands

    Devastating Earthquakes Will Test Venezuela’s Newfound Alliance With U.S.

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by