# macOS.Gaslight — DPRK-aligned Rust Backdoor & Infostealer with Analyst-Targeting Prompt-Injection Anti-Analysis (Telegram Bot API C2)

> macOS.Gaslight is a Rust-based persistent backdoor and infostealer for macOS, attributed with high confidence to DPRK-aligned activity. It is notable for a novel anti-analysis technique: a 3.5 KB blob of 38 fabricated 'system' messages designed to disrupt LLM-assisted malware analysis (and mislead human analysts) rather than evade sandboxes. It uses Telegram Bot API getUpdates polling for C2 with AES-GCM encryption and certificate pinning, persists via a masquerading LaunchAgent, and stages a base64-encoded Python stealer that harvests browser data, keychain credentials, and system data for exfiltration over Telegram.

- **Published:** 2026-06-23T00:00:00Z
- **Last reviewed:** 2026-09-01T13:57:01.909Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0920
- **ID:** TL-2026-0920
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 28 (full data via the Threadlinqs MCP server — Purple tier)

## Description

macOS.Gaslight is a Rust-compiled, ad-hoc-signed Mach-O implant for macOS (aarch64 primary; the staged Python stealer also supports x86_64) analyzed by SentinelLABS and published on 23 June 2026. SentinelLABS attributes the sample to a DPRK-aligned activity cluster with HIGH confidence based on Apple XProtect detection under the MACOS_BONZAI_COBUCH rule (the BONZAI signature family is associated by SentinelLABS with North Korean operations) and a sibling sample detected by the AIRPILE rule, also tied to DPRK activity. The malware sits within the lineage of DPRK macOS tooling such as RustBucket, KandyKorn, and NimDoor.

The defining feature of macOS.Gaslight is an analyst-targeting prompt-injection payload: a ~3.5 KB Markdown-fenced blob containing 38 fabricated 'system' messages that imitate an LLM triage harness scaffold using {{DATA}} delimiters. The fake messages describe token expiry, out-of-memory kills, disk exhaustion, injection vulnerabilities, and static-analysis flags, with the objective of pushing an LLM agent into aborting, truncating, or refusing analysis. SentinelLABS characterizes this as the first documented harness-spoofing cascade — earlier samples used single injected blocks — and notes the implant 'attacks the agent's perception, rather than the sandbox it runs in.' Notably absent are conventional anti-analysis tricks such as VM detection, debugger evasion, or sandbox-specific behavior.

For command and control, the Rust core uses a Telegram Bot API getUpdates polling loop, with single-instance locking achieved via the Telegram Conflict error response. It exposes an interactive shell with six verbs (help, id, shell, kill, upload, stop) plus evidence of a seventh 'focus' command. Transport security uses the aes-gcm 0.10.3 crate for AES-GCM payload encryption with a fresh nonce per message generated via CCRandomGenerateBytes, an AES key supplied at runtime (not embedded), and certificate pinning via SecTrustSetAnchorCertificatesOnly to block standard proxy CA interception while still honoring system proxy settings via SCDynamicStoreCopyProxies. Runtime behavior is driven by a 15-field serde configuration schema (tg_room_id, github_token, github_repo, github_polling_interval, main_upload_url, main_base_url, aes_key, payload_path_linux, payload_path_macos, persist_name_linux, persist_name_macos, persist_type_linux, persist_type_macos, init_python_enable, persist_enable). The presence of Linux and GitHub fields not exercised in the sample indicates a broader, cross-platform operator toolkit. An OPSEC feature redacts the bot token in runtime output when a URL path contains the bytes for 'file' (0x656c6966 little-endian), substituting the placeholder 'file/token:redacted' to prevent token recovery from logs and crash artifacts.

The implant resolves APIs at runtime via dlsym (avoiding the static symbol table), locates its own executable via __NSGetExecutablePath, executes processes with execvp (with a posix_spawnp alternative), and creates an IOPMAssertionCreateWithName power-management assertion to prevent system sleep during polling/collection. Persistence is via a LaunchAgent labeled com.apple.system.services.activity (masquerading within the com.apple.* namespace), written with an absolute executable path and gated by the persist_enable serde field.

Data collection is handled by a base64-encoded Python stealer (~6.6 KB encoded) staged at runtime by a ~2 KB bash installer. The installer fetches a standalone CPython runtime (Python 3.10.18, build 20250708) from the astral-sh/python-build-standalone project, supporting arm64 and x86_64. The stealer collects Chrome, Brave, Firefox, and Safari browser data; terminal command histories; installed application lists; running processes (ps aux); a system profile (system_profiler); and a raw copy of login.keychain-db. Collected data is archived to temp/collected_data.zip and uploaded via the Telegram multipart attach mechanism. Widespread emoji use and strict comment headers in the stealer suggest AI-assisted code generation. The sample was uploaded to VirusTotal on 22 May 2026 and surfaced via an early-June 2026 Apple XProtect update, despite being previously undetected on VirusTotal.

## MITRE ATT&CK

- T1587 Develop Capabilities
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1106 Native API
- T1543 Create or Modify System Process
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1553 Subvert Trust Controls
- T1555 Credentials from Password Stores
- T1539 Steal Web Session Cookie
- T1217 Browser Information Discovery
- T1518 Software Discovery
- T1057 Process Discovery
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1005 Data from Local System
- T1119 Automated Collection
- T1074 Data Staged
- T1560 Archive Collected Data
- T1102 Web Service
- T1071 Application Layer Protocol
- T1573 Encrypted Channel
- T1132 Data Encoding
- T1567 Exfiltration Over Web Service
- T1041 Exfiltration Over C2 Channel
- T1020 Automated Exfiltration
- T1059.006 Command and Scripting Interpreter
- T1059.004 Command and Scripting Interpreter
- T1543.001 Create or Modify System Process
- T1036.005 Masquerading
- T1555.001 Credentials from Password Stores
- T1555.003 Credentials from Password Stores
- T1552.003 Unsecured Credentials
- T1102.002 Web Service
- T1573.001 Encrypted Channel
- T1105 Ingress Tool Transfer
- AML.T0051.001 LLM Prompt Injection

## Sources

- [macOS.Gaslight: Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox](https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox/)
- [BlueNoroff | How DPRK's macOS RustBucket Seeks to Evade Analysis and Detection](https://www.sentinelone.com/blog/bluenoroff-how-dprks-macos-rustbucket-seeks-to-evade-analysis-and-detection/)
- [macOS NimDoor | DPRK Threat Actors Target Web3 and Crypto Platforms with Nim-Based Malware](https://www.sentinelone.com/labs/macos-nimdoor-dprk-threat-actors-target-web3-and-crypto-platforms-with-nim-based-malware/)
- [DPRK Crypto Theft | macOS RustBucket Droppers Pivot to Deliver KandyKorn Payloads](https://www.sentinelone.com/blog/dprk-crypto-theft-macos-rustbucket-droppers-pivot-to-deliver-kandykorn-payloads/)
- [macOS FlexibleFerret | Further Variants of DPRK Malware Family Unearthed](https://www.sentinelone.com/blog/macos-flexibleferret-further-variants-of-dprk-malware-family-unearthed/)
- [New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs (The Hacker News)](https://thehackernews.com/2026/04/new-wave-of-dprk-attacks-uses-ai.html)
- [Google Threat Report Links AI-powered Malware to DPRK Crypto Theft (Decrypt)](https://decrypt.co/347781)
- [astral-sh/python-build-standalone (standalone CPython distribution used to stage the stealer)](https://github.com/astral-sh/python-build-standalone)
- [aes-gcm crate (RustCrypto) — AES-GCM implementation referenced (v0.10.3)](https://crates.io/crates/aes-gcm)
- [Backdoor-Powered Prompt Injection Attacks Nullify Defense Methods (arXiv)](https://arxiv.org/pdf/2510.03705)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0920
