macOS.Gaslight is a Rust-based macOS implant that combines backdoor and infostealer functionality and has been assessed with high confidence as part of DPRK-aligned activity. The malware is notable for embedding prompt-injection content intended to disrupt or mislead LLM-assisted malware triage workflows, using dozens of fabricated system-style messages designed to induce automated analysis agents to abort, truncate, or refuse analysis. Beyond this AI-targeting feature, it operates as a persistent remote access implant with data theft capabilities.
On compromised Macs, macOS.Gaslight provides an interactive shell for operator tasking, including command execution, process termination, file upload, and implant control. It maintains persistence through a LaunchAgent masquerading as an Apple service and can prevent system sleep to keep its command loop active. Its command-and-control channel uses Telegram Bot API polling, with encrypted payload exchange, certificate pinning, and proxy awareness to improve resilience and hinder inspection.
The malware includes a staged Python-based collection component that can be enabled on demand. This stealer harvests browser data from Chrome, Brave, Firefox, and Safari, collects terminal histories, enumerates installed applications and running processes, gathers system profile information, and steals contents from the macOS login keychain for exfiltration. Collected data is archived and sent back to the operator over Telegram. The implant can also retrieve a standalone Python runtime at execution time to support this collection workflow.
The malware has been linked to North Korean threat activity through overlap with Apple detection families associated with DPRK operations, including BONZAI and related AIRPIPE-linked activity. Its combination of conventional macOS persistence and theft tradecraft with explicit prompt-injection aimed at AI-assisted analysis makes it a notable example of malware designed to target both endpoints and defender automation workflows.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
SentinelOne did not name any initial access mechanism, leaving open the question of whether attackers distribute the malware through phishing, trojanized software, or another method. TechRadar says that the malware infects devices by whatever means necessary, but still cites phishing.
The malware uses a LaunchAgent with the label com.apple.system.services.activity, impersonating Apple’s own namespace, to achieve persistence.
The shell supports six commands, including running shell code, killing processes by ID, uploading files, and stopping the implant entirely.
It resolves its API calls at runtime through dlsym so as to avoid embedding them in the static symbol table
To maintain persistence, macOS.Gaslight creates a LaunchAgent (com.apple.system.services.activity) that mimics a legitimate Apple service
Once the Python environment is staged, the stealer harvests Chrome, Brave, Firefox, and Safari browser data...
Once the Python environment is staged, the stealer harvests Chrome, Brave, Firefox, and Safari browser data, terminal histories, installed application listings, a running process snapshot, a system profile, and a raw copy of login.keychain-db.
An embedded Base64-encoded Python script allows the collection of browser data, Terminal history, hardware and software information
To stay hidden in transit, the malware's command channel used Telegram's Bot API, with traffic encrypted and protected by certificate pinning to defeat network inspection.
It also reads the host’s proxy settings and routes traffic accordingly, so it still reaches the operator on networks that force outbound connections through a corporate proxy.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously undocumented Rust-based macOS implant that embeds fake prompt-injection messages to mislead AI-assisted malware analysis while also acting as a remote backdoor and infostealer. It can execute shell commands, upload files, terminate processes, collect browser data, Terminal history, hardware/software details, and Keychain credentials, maintain persistence via a LaunchAgent masquerading as an Apple service, and exfiltrate stolen data through Telegram Bot API infrastructure.
A North Korea-linked Rust-based macOS implant and infostealer that uses Telegram Bot API for C2, persists via a LaunchAgent, supports interactive shell commands, and can deploy a gated Python stealer to collect browser data, terminal histories, process and system information, and keychain data. It is notable for embedding prompt-injection content intended to mislead AI-assisted malware analysts.
Rust-based macOS backdoor that steals browser credentials, terminal histories, installed app listings, and the macOS login keychain file; provides an interactive shell; deploys a Python data collection module on demand; exfiltrates archived data via the Telegram Bot API; and persists via a disguised LaunchAgent.
A North Korea-linked macOS Rust implant that embeds prompt-injection content to disrupt AI-assisted malware triage while also functioning as a backdoor and infostealer. It provides an interactive shell, steals browser data from Chrome, Brave, Firefox, and Safari, collects terminal histories, installed-app lists, and the macOS login keychain, stages Python modules on demand, and uses Telegram Bot API communications with encryption and certificate pinning.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.