macOS.Gaslight - Rust Backdoor with AI-Analysis Evasion & Prompt Injection

macOS.Gaslight (TL-2026-0994) is a critical-severity malware campaign, first published 2026-06-28. It is attributed to Kimsuky (North Korea) with high confidence, maps to 33 MITRE ATT&CK techniques (T1027, T1036, T1037), and is covered by 9 detection rules and 32 indicators of compromise.

Key facts for TL-2026-0994

Threat ID
TL-2026-0994
Severity
CRITICAL
Status
ACTIVE
Category
MALWARE
First published
2026-06-28
Last reviewed
2026-06-28
Attribution
Kimsuky
Attribution confidence
HIGH
Nation-state nexus
North Korea
Motivation
ESPIONAGE
Target sectors
technology, research, government administration, defense, academia, news - media
Target regions
North America, Asia-Pacific, Europe
Detection rules
9
Indicators of compromise
32

Malware and tooling in macOS.Gaslight

Malware and tooling: Angryboy Spyware, Credential Harvesting Framework, Gaslight.A, KimuAgent, macOS.Gaslight, Custom Rust-based C2, Rust

macOS.Gaslight is a Rust-based backdoor and information-stealing malware that employs novel anti-analysis techniques using embedded fake error messages and prompt injection strings to evade AI-powered malware analysis tools. Attributed with high confidence to North Korean threat actors, the malware combines traditional backdoor functionality with sophisticated social engineering against automated analysis pipelines.

How macOS.Gaslight works

macOS.Gaslight represents a significant evolution in anti-analysis malware design, targeting a growing blind spot in the cybersecurity ecosystem: LLM-powered and AI-assisted malware triage systems. Rather than traditional anti-analysis techniques (anti-VM, anti-debugging, anti-sandboxing), Gaslight embeds 38 fabricated system error messages and prompt injection payloads (totaling 3.5 KB) within the Rust binary to confuse and misdirect AI analysis tools. When analyzed by ChatGPT, Claude, or similar LLM-based malware analysis platforms, the malware generates false error traces and misleading debugging information that cause the AI to mischaracterize the threat or provide incorrect analysis. The backdoor component establishes command-and-control communication channels for remote code execution, while the information stealer component exfiltrates sensitive data from the infected macOS system. The malware's Rust implementation provides both code obfuscation benefits and cross-platform compilation flexibility. This attack represents a new category of "AI-aware" evasion targeting the emerging ecosystem of AI-powered security tools. The threat demonstrates North Korean threat actor sophistication in adapting attacks to counter defensive technologies. The use of Rust for malware development reflects a trend among advanced persistent threat (APT) groups seeking language-based evasion advantages. Execution on macOS indicates targeting of creative professionals, engineers, and researchers—high-value targets in North Korean espionage operations. Primary infection vectors remain under investigation but likely include supply chain compromise, trojanized developer tools, or macOS-specific delivery mechanisms (DMG files, PKG installers). The malware's ability to evade both static analysis tools and dynamic sandbox detection through AI confusion represents a critical gap in current detection methodologies.

MITRE ATT&CK techniques used in TL-2026-0994

stealth

T1027 Obfuscated Files or Information

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution

Persistence

T1037 Boot or Logon Initialization Scripts; T1543 Create or Modify System Process; T1556 Modify Authentication Process

Exfiltration

T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol

Credential Access

T1056 Input Capture; T1555 Credentials from Password Stores

Discovery

T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1518 Software Discovery

Execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1572 Protocol Tunneling

Initial Access

T1195 Supply Chain Compromise; T1566 Phishing

Impact

T1486 Data Encrypted for Impact

persistence

T1547.002 Authentication Package

Privilege Escalation

T1548 Abuse Elevation Control Mechanism

defense-impairment

T1553 Subvert Trust Controls; T1578 Modify Cloud Compute Infrastructure; T1685 Disable or Modify Tools

Resource Development

T1583 Acquire Infrastructure; T1587 Develop Capabilities

defense-evasion

T1633 Virtualization/Sandbox Evasion

Timeline of macOS.Gaslight

  • Estimated development period: Rust-based backdoor framework designed with AI evasion capabilities
  • Initial detection by SentinelOne Labs during routine threat monitoring; Gaslight malware identified in the wild
  • Evidence of active distribution via phishing and supply chain compromise targeting macOS users
  • Technical analysis and infrastructure tracking begin linking malware to North Korean threat actor Kimsuky/APT43
  • Security researchers document effectiveness of prompt injection payloads in evading LLM-powered malware analysis systems
  • SentinelOne Labs and BleepingComputer publish detailed technical analysis and disclosure of macOS.Gaslight threat
  • CISA and vendor security teams issue alerts recommending detection and remediation procedures
  • Threat remains active in the wild with continued targeting of macOS systems and developer infrastructure

Threats related to macOS.Gaslight

Detection coverage for TL-2026-0994

As of 2026-06-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0994 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats