North Korea-linked Gaslight macOS malware uses fake error messages to mislead AI analysis tools

Researchers found a new macOS malware family called Gaslight that steals data and gives attackers backdoor access while also trying to confuse AI-based malware analysis tools. SentinelOne says the Rust-based sample contains about 3.5 KB of embedded prompt-injection text and 38 fake system, crash, and debug messages meant to make large language model analysis pipelines abort or mistrust their own results; the company attributes the malware with high confidence to a North Korean-linked threat actor.
Why it matters: This matters because it shows attackers are adapting malware to interfere with newer AI-assisted security workflows, not just traditional sandboxes and analysts. Defenders using automated malware triage should validate AI findings against manual and non-LLM tooling, and macOS users and admins should treat the sample as a real backdoor and infostealer threat.

Sources

In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs
SecurityWeek News 2026.06.26 62% relevant
The roundup cites the same newly reported Gaslight macOS backdoor as one of the week's notable developments, but provides no meaningful new technical detail beyond acknowledging the malware's existence.
New macOS malware embeds fake errors to confuse AI analysis tools
Lawrence Abrams 2026.06.25 100% relevant
This article establishes a distinct new event: the first reporting here is about the newly identified Gaslight macOS malware family, its embedded prompt-injection anti-analysis technique, and its attribution to a North Korean-linked actor.
← Back to all stories