Moonlock researchers discovered Gaslight, a Rust-based macOS malware linked to North Korean threat actors. It spreads via social-engineering lures such as fake recruiter outreach and developer testing requests. Once installed, it steals browser data, terminal history, installed app lists, and the encrypted Keychain file, while also functioning as a backdoor. Its standout feature is prompt-injection-style evasion: 38 fabricated system messages embedded in plain text attempt to confuse AI-driven security analysis tools into halting review before flagging the file as malicious. Apple added XProtect detection in early June 2025, and 29 VirusTotal vendors now detect it. CISOs are advised to ensure macOS endpoint controls are current, train users on North Korean social-engineering patterns, and validate AI-assisted triage workflows against prompt-injection manipulation.

4m read timeFrom securityboulevard.com
Post cover image
Table of contents
What happenedWho is affectedWhy CISOs should care3 practical actions
265 Impressions