SentinelLABS reported a Rust-based macOS backdoor and infostealer dubbed macOS.Gaslight that uses the Telegram Bot API for command-and-control, protected by AES-GCM encryption and certificate-pinned TLS. The implant supports an interactive shell, establishes persistence through a LaunchAgent, and deploys a configurable Python collection module to steal browser data, terminal histories, process listings, system profiles, and a copy of login.keychain-db. Researchers said the malware also redacts its Telegram bot token from runtime output, making credential recovery from logs and crash artifacts more difficult.
The researchers linked the implant with high confidence to a DPRK-aligned macOS activity cluster and said it overlaps with Apple XProtect detections in the BONZAI family, with related ties to AIRPIPE. A notable feature is an embedded 3.5 KB prompt-injection payload containing 38 fabricated system messages designed to manipulate LLM-assisted malware triage workflows into refusing or aborting analysis, marking the sample as a case of malware directly targeting AI-enabled defensive processes as well as traditional endpoint analysis.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
A GitHub security advisory disclosed a high-severity permission-gate bypass in the rtk project's `rewrite` decision path when used as the Claude Code PreToolUse hook. The issue allowed commands beginning with an allowed prefix such as `git` to conceal unauthorized shell commands via separators like newlines, `&`, `$()`, and backticks, potentially leading to arbitrary hidden command execution.
SentinelLABS published analysis of a Rust-based macOS implant and infostealer dubbed macOS.Gaslight, describing Telegram Bot API polling for C2, AES-GCM encryption, certificate-pinned TLS, LaunchAgent persistence, and data theft capabilities. The report also assessed with high confidence that the implant belongs to a DPRK-aligned macOS activity cluster and highlighted an embedded prompt-injection payload aimed at disrupting LLM-assisted malware analysis.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 66 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
13 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcesecurityaffairs.com
Open sourcexakep.ru
Open sourcecybersecuritynews.com
Open sourcegithub.com
Open sourceblog.nviso.eu
Open sourcesentinelone.com
Open sourcedocs.rs
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.