SentinelLABS has analyzed macOS.Gaslight, a DPRK-linked Rust macOS implant with a novel anti-analysis technique: a 3.5 KB embedded prompt-injection payload containing 38 fabricated 'system' messages designed to mislead LLM-assisted triage pipelines into aborting analysis. Beyond this, the implant features a Telegram Bot API C2 with AES-GCM encryption and certificate pinning, a bot-token self-redaction mechanism, a Python-based credential stealer (harvesting browser data, keychains, and terminal history), LaunchAgent persistence masquerading as an Apple system service, and a runtime-fetched standalone CPython interpreter. The prompt injection is more sophisticated than previously documented examples, using a 38-message harness-spoofing cascade rather than a single injected block. Defenders building LLM-assisted analysis pipelines are warned to treat sample contents as adversarial input.

10m read timeFrom sentinelone.com
Post cover image
Table of contents
Executive SummaryBackgroundCommand & Control | Telegram Bot APITransport Hardening | AES-GCM Over Pinned TLSOperator Access | An Interactive ShellThe 15-Field Cross-Platform Operator ConfigCollection | A Gated Python Stealer With Its Own Runtime Supply ChainPersistence | An Apple System-Service MasqueradeOPSEC | Bot-Token Self-RedactionA Prompt Injection That Targets the AnalystConclusionIndicators of Compromise
402 Impressions