Threat reportMalwareTL-2026-0920
macOS.Gaslight — DPRK-aligned Rust Backdoor & Infostealer with Analyst-Targeting Prompt-Injection Anti-Analysis (Telegram Bot API C2)
macOS.Gaslight (TL-2026-0920), also tracked as macOS.Gaslight, is a high-severity malware campaign, first published 2026-06-23 and last reviewed 2026-09-01. It is linked to a North Korea-nexus actor with high confidence, affects Apple macOS, maps to 38 MITRE ATT&CK / ATLAS techniques (AML.T0051.001, T1005, T1020), and is covered by 9 detection rules and 28 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 38MITRE ATT&CK / ATLAS
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 28Indicators of compromise
Key facts for TL-2026-0920
- Threat ID
- TL-2026-0920
- Also known as
- macOS.Gaslight, Gaslight, MACOS_BONZAI_COBUCH (XProtect rule)
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea
- Motivation
- FINANCIAL
- Target sectors
- cryptocurrency, blockchain, financial, technology, web3
- Target regions
- Global, North America, Europe, Asia
- Detection rules
- 9
- Indicators of compromise
- 28
- Updates
- 2026-09-01 · revalidated 1× · latest source
Malware and tooling in macOS.Gaslight
Malware and tooling: BONZAI / AIRPILE (XProtect), macOS.Gaslight, Telegram Bot API custom Rust C2, astral-sh/python-build-standalone CPython 3.10.18 (build 20250708)
How macOS.Gaslight works
macOS.Gaslight is a Rust-based persistent backdoor and infostealer for macOS, attributed with high confidence to DPRK-aligned activity. It is notable for a novel anti-analysis technique: a 3.5 KB blob of 38 fabricated 'system' messages designed to disrupt LLM-assisted malware analysis (and mislead human analysts) rather than evade sandboxes. It uses Telegram Bot API getUpdates polling for C2 with AES-GCM encryption and certificate pinning, persists via a masquerading LaunchAgent, and stages a base64-encoded Python stealer that harvests browser data, keychain credentials, and system data for exfiltration over Telegram.
macOS.Gaslight is a Rust-compiled, ad-hoc-signed Mach-O implant for macOS (aarch64 primary; the staged Python stealer also supports x86_64) analyzed by SentinelLABS and published on 23 June 2026. SentinelLABS attributes the sample to a DPRK-aligned activity cluster with HIGH confidence based on Apple XProtect detection under the MACOS_BONZAI_COBUCH rule (the BONZAI signature family is associated by SentinelLABS with North Korean operations) and a sibling sample detected by the AIRPILE rule, also tied to DPRK activity. The malware sits within the lineage of DPRK macOS tooling such as RustBucket, KandyKorn, and NimDoor.
The defining feature of macOS.Gaslight is an analyst-targeting prompt-injection payload: a ~3.5 KB Markdown-fenced blob containing 38 fabricated 'system' messages that imitate an LLM triage harness scaffold using {{DATA}} delimiters. The fake messages describe token expiry, out-of-memory kills, disk exhaustion, injection vulnerabilities, and static-analysis flags, with the objective of pushing an LLM agent into aborting, truncating, or refusing analysis. SentinelLABS characterizes this as the first documented harness-spoofing cascade — earlier samples used single injected blocks — and notes the implant 'attacks the agent's perception, rather than the sandbox it runs in.' Notably absent are conventional anti-analysis tricks such as VM detection, debugger evasion, or sandbox-specific behavior.
For command and control, the Rust core uses a Telegram Bot API getUpdates polling loop, with single-instance locking achieved via the Telegram Conflict error response. It exposes an interactive shell with six verbs (help, id, shell, kill, upload, stop) plus evidence of a seventh 'focus' command. Transport security uses the aes-gcm 0.10.3 crate for AES-GCM payload encryption with a fresh nonce per message generated via CCRandomGenerateBytes, an AES key supplied at runtime (not embedded), and certificate pinning via SecTrustSetAnchorCertificatesOnly to block standard proxy CA interception while still honoring system proxy settings via SCDynamicStoreCopyProxies. Runtime behavior is driven by a 15-field serde configuration schema (tg_room_id, github_token, github_repo, github_polling_interval, main_upload_url, main_base_url, aes_key, payload_path_linux, payload_path_macos, persist_name_linux, persist_name_macos, persist_type_linux, persist_type_macos, init_python_enable, persist_enable). The presence of Linux and GitHub fields not exercised in the sample indicates a broader, cross-platform operator toolkit. An OPSEC feature redacts the bot token in runtime output when a URL path contains the bytes for 'file' (0x656c6966 little-endian), substituting the placeholder 'file/token:redacted' to prevent token recovery from logs and crash artifacts.
The implant resolves APIs at runtime via dlsym (avoiding the static symbol table), locates its own executable via __NSGetExecutablePath, executes processes with execvp (with a posix_spawnp alternative), and creates an IOPMAssertionCreateWithName power-management assertion to prevent system sleep during polling/collection. Persistence is via a LaunchAgent labeled com.apple.system.services.activity (masquerading within the com.apple.* namespace), written with an absolute executable path and gated by the persist_enable serde field.
Data collection is handled by a base64-encoded Python stealer (~6.6 KB encoded) staged at runtime by a ~2 KB bash installer. The installer fetches a standalone CPython runtime (Python 3.10.18, build 20250708) from the astral-sh/python-build-standalone project, supporting arm64 and x86_64. The stealer collects Chrome, Brave, Firefox, and Safari browser data; terminal command histories; installed application lists; running processes (ps aux); a system profile (system_profiler); and a raw copy of login.keychain-db. Collected data is archived to temp/collected_data.zip and uploaded via the Telegram multipart attach mechanism. Widespread emoji use and strict comment headers in the stealer suggest AI-assisted code generation. The sample was uploaded to VirusTotal on 22 May 2026 and surfaced via an early-June 2026 Apple XProtect update, despite being previously undetected on VirusTotal.
MITRE ATT&CK / ATLAS techniques used in TL-2026-0920
Initial Access
AML.T0051.001 LLM Prompt Injection
Collection
T1005 Data from Local System; T1074 Data Staged; T1119 Automated Collection; T1560 Archive Collected Data
Exfiltration
T1020 Automated Exfiltration; T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1036.005 Masquerading; T1140 Deobfuscate/Decode Files or Information
Discovery
T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1217 Browser Information Discovery; T1518 Software Discovery
Execution
T1059 Command and Scripting Interpreter; T1059.004 Command and Scripting Interpreter; T1059.006 Command and Scripting Interpreter; T1106 Native API
Command and Control
T1071 Application Layer Protocol; T1102 Web Service; T1102.002 Web Service; T1105 Ingress Tool Transfer; T1132 Data Encoding; T1573 Encrypted Channel; T1573.001 Encrypted Channel
execution
Credential Access
T1539 Steal Web Session Cookie; T1552.003 Unsecured Credentials; T1555 Credentials from Password Stores; T1555.001 Credentials from Password Stores; T1555.003 Credentials from Password Stores
Persistence
T1543 Create or Modify System Process; T1543.001 Create or Modify System Process
defense-impairment
Resource Development
Affected products and versions in macOS.Gaslight
- Apple — macOS
Vulnerable versions: macOS on Apple Silicon (aarch64); macOS on Intel (x86_64, via Python stealer)
Remediation for macOS.Gaslight
Immediate actions
- Block and alert on the published SHA-256 hashes (Mach-O, Python payload, bash installer, sibling BONZAI sample) across EDR and email/file gateways
- Hunt for the LaunchAgent label com.apple.system.services.activity in ~/Library/LaunchAgents and /Library/LaunchAgents
- Ensure Apple XProtect is current; rules MACOS_BONZAI_COBUCH and AIRPILE detect this family
- Alert on outbound connections to api.telegram.org from non-browser, unsigned/ad-hoc-signed macOS processes
- Hunt for runtime fetches of astral-sh/python-build-standalone CPython 3.10.18 (build 20250708) from non-developer endpoints
Workarounds
- Restrict Telegram Bot API (api.telegram.org) egress where not business-required
- Apply egress allowlisting rather than relying on TLS CA interception — this malware pins certificates and ignores injected proxy CAs
Longer-term hardening
- Deploy behavioral EDR on macOS that flags LaunchAgent creation by ad-hoc-signed binaries and login.keychain-db access by non-Apple processes
- Enforce allowlisting / notarization-gating so ad-hoc-signed Mach-O binaries cannot execute
- Treat malware artifacts and any embedded 'system'/instruction text as untrusted DATA in LLM-assisted analysis pipelines; sandbox LLM analysis and never let analyzed content steer agent control flow
- Monitor for anomalous IOPMAssertion power-assertions and dlsym-heavy runtime API resolution
Timeline of macOS.Gaslight
- SentinelLABS documents RustBucket, an early DPRK macOS Rust backdoor that evades analysis and detection — establishing the DPRK Rust-on-macOS lineage macOS.Gaslight extends.
- Build date (20250708) of the standalone CPython 3.10.18 runtime (astral-sh/python-build-standalone) that the bash installer fetches to run the Python stealer.
- Reporting describes a new wave of DPRK attacks leveraging AI-inserted npm malware, fake firms, and RATs — the broader AI-assisted DPRK tooling trend in which macOS.Gaslight's AI-generated stealer and anti-LLM payload sit.
- macOS.Gaslight sample uploaded to VirusTotal, where it was initially undetected.
- Early-June 2026 Apple XProtect update surfaced the Mach-O sample (rule MACOS_BONZAI_COBUCH); sibling sample caught by AIRPILE rule.
- Security Affairs and Cyber Security News publish same-day coverage summarizing the SentinelOne findings.
- Four SHA-256 IOCs published (Mach-O implant, sibling BONZAI sample, Python payload, bash installer) plus LaunchAgent label and ad-hoc signing ID.
- First documented 'harness-spoofing cascade': 38 fabricated system messages targeting LLM-assisted analysis, an escalation over prior single-block prompt injections.
- SentinelLABS attributed the sample to a DPRK-aligned activity cluster with HIGH confidence based on BONZAI/AIRPILE XProtect detections.
- SentinelLABS published analysis of macOS.Gaslight, documenting the analyst-targeting prompt-injection technique.
- The Hacker News and GBHackers publish follow-up coverage amplifying the SentinelOne research, including researcher Phil Stokes's quote: 'It attacks the agent's perception, rather than the sandbox it runs in.'
Update history for TL-2026-0920
- 2026-09-01 — macOS.Gaslight: Rust-Based DPRK-Aligned Backdoor Uses Prompt Injection Against LLM Analyst Tools: What changed No severity/exploitability/status/attribution escalation — the newer report restates the same HIGH/ACTIVE/ACTIVE assessment. It labels motivation ESPIONAGE versus the existing record's FINANCIAL and drops the actor alias list,
Sources cited for macOS.Gaslight
- macOS.Gaslight: Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox
- BlueNoroff | How DPRK's macOS RustBucket Seeks to Evade Analysis and Detection
- macOS NimDoor | DPRK Threat Actors Target Web3 and Crypto Platforms with Nim-Based Malware
- DPRK Crypto Theft | macOS RustBucket Droppers Pivot to Deliver KandyKorn Payloads
- macOS FlexibleFerret | Further Variants of DPRK Malware Family Unearthed
- New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs (The Hacker News)
- Google Threat Report Links AI-powered Malware to DPRK Crypto Theft (Decrypt)
- astral-sh/python-build-standalone (standalone CPython distribution used to stage the stealer)
- aes-gcm crate (RustCrypto) — AES-GCM implementation referenced (v0.10.3)
- Backdoor-Powered Prompt Injection Attacks Nullify Defense Methods (arXiv)
Detection coverage for TL-2026-0920
As of 2026-09-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0920 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.