A newly discovered macOS malware called 'Gaslight,' attributed with high confidence to a North Korean threat actor, embeds 38 fake system error messages within its Rust binary to confuse AI-assisted malware analysis tools. The 3.5 KB payload contains fabricated crash reports, memory dumps, token expiration warnings, and SQL injection alerts formatted with Markdown to mimic legitimate debugging data. Rather than evading sandbox execution, the technique targets LLM-based triage agents by injecting content designed to make them doubt their own session validity, potentially causing them to abort or truncate analysis. SentinelOne researchers note this represents a novel anti-analysis approach specifically targeting AI-powered security pipelines, though they have not yet demonstrated a successful bypass of real platforms.

3m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Related Articles:
345 Impressions