#Gaslight

Malware/Tool

2026-06-23 • macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox

Gaslight is a Rust-based macOS backdoor and information stealer associated with DPRK-aligned activity. The ad hoc-signed Mach-O implant uses Telegram Bot API polling for command and control, with AES-GCM-encrypted payloads over certificate-pinned TLS, and supports remote command execution and data exfiltration. It collects browser data from Chrome, Brave, Firefox, and Safari, Terminal command histories, installed applications, running processes, system hardware and software profiles, and the macOS login keychain database. A configurable LaunchAgent masquerading in Apple's com.apple namespace provides persistence. The implant also embeds fabricated system messages intended to induce an LLM-assisted malware-analysis workflow to abort or refuse analysis and redacts its Telegram bot token from runtime output.

Tagged Reports

« Back