HomeSecurityGaslight: New macOS Malware with Prompt Injection against AI Tools

Gaslight: New macOS Malware with Prompt Injection against AI Tools

Gaslight is a new macOS malware written in Rust that uses a groundbreaking prompt injection technique to trick AI-based analysis tools. Gaslight does not attack the sandbox or the operating system, but directly targets the perception of the AI ​​agent analyzing the sample, causing it to refuse or abort the analysis. According to SentinelOne researchers , the tool is believed to be the work of a group associated with North Korea .

See also: Google strengthens Chrome Agentic AI against Prompt Injection attacks

Gaslight macOS malware prompt injection AI analysis tools

SentinelLabs researcher Phil Stokes described the malware’s most distinctive feature: “ It contains an embedded chain of crafted system failure messages, designed to make an LLM-assisted triage agent doubt its own session .” This technique represents a significant advancement in detection evasion, as it shifts the focus from traditional sandbox evasion to AI manipulation .

Gaslight: Technical Architecture and Prompt Injection

At the core of Gaslight’s architecture is a Command & Control (C2) channel based on the Telegram Bot API with a polling loop, allowing the operator to issue commands via an interactive shell. The shell supports six main commands: help , id , shell (execute commands via execvp), kill (terminate a process via PID), upload (export files via Telegram’s “attach://” mechanism), and stop . The researchers also found evidence of a seventh command named “focus” , the functionality of which remains unclear. For persistence in the system, Gaslight uses a LaunchAgent with the tag “com.apple.system.services.activity” , disguised as a legitimate Apple service .

The most innovative feature of Gaslight is its built-in payload prompt injection — a 3.5 KB block in Markdown format containing 38 fabricated “system” messages , delimited by {{DATA}} tokens . These fake messages include token expiration alerts, out -of-memory kills , disk exhaustion , as well as fake injection vulnerability warnings and static analysis flags. The goal is to convince an LLM-assisted analysis tool to mark the binary as harmless or to abort analysis altogether.

See also: Attacks on AI Models – Model Inversion and Prompt Injection

Gaslight info stealer

As an infostealer, Gaslight embeds a 6.6 KB Python script encoded in Base64, which collects Terminal command history, lists of installed applications, snapshots of running processes, hardware and software profiles, the macOS Keychain, as well as data from the Chrome, Brave, Firefox and Safari. The collected data is compressed into a ZIP and uploaded via Telegram. Notably, the malware “self-certifies,” removing the Telegram bot token from runtime outputs and crash artifacts, thus hiding a crucial detection element.

The Objective-See Foundation has added the OSX.Gaslight sample to the public Mac malware repository for further analysis by the community. At the same time, the researchers emphasize that Gaslight represents an evolution over previous prompt injection techniques — while earlier versions used a single injected block to prevent AI triage, the malware escalates this tactic with a chain of 38 fake messages , making the deception much more convincing.

See also: Meta's Llama firewall bypassed via Prompt Injection

Gaslight: New macOS Malware with Prompt Injection against AI Tools

Protection from the threat

To protect against this malware and similar threats, experts recommend treating any binary analyzed as adversarial input — AI tools should not blindly trust the prompt scaffold. Additionally, it is recommended to cross-check AI results with static analysis and manual reverse engineering, monitor the network for suspicious Telegram Bot API traffic , and ensure that Apple XProtect and macOS security patches are up-to-date to detect known signatures like MACOS_BONZAI_COBUCH . According to The Hacker News, Gaslight marks a critical shift in malware evasion tactics, requiring security teams to reevaluate their AI-based analysis pipelines.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS