All Posts
Anomali Cyber Watch
1
min read

Anomali Cyber Watch: Sample 3

Published on
December 24, 2025
Table of Contents

h2

h3

At a Glance

Attack Patterns
85
System Information Discovery
4
Process Discovery
3
Ingress Tool Transfer
3
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
3
Web Service: Bidirectional Communication
2
Exfiltration Over C2 Channel
2
User Execution: Malicious File
2
Command and Scripting Interpreter: Powershell
2
Command and Scripting Interpreter: Windows Command Shell
2
Scheduled Task/Job: Scheduled Task
2
Regions & Countries
5
Source-Region: Asia 40.0%
Asia 20.0%
Europe 20.0%
Source-Region: Europe 20.0%
Industries
5
Government / Government National
1
Technology
1
Government
1
Defense
1
Automotive
1
* Frequency counts reflect mentions across collected reports
Story #1  |  June 23, 2026

macOS.Gaslight: DPRK-Linked Rust Implant Embeds Prompt Injection to Disrupt AI-Assisted Triage

▶ expand
Researchers analyzed macOS.Gaslight, a Rust-based macOS backdoor and infostealer assessed with high confidence to be linked to North Korea-aligned threat activity. The sample, first uploaded to VirusTotal on May 22, 2026 and subsequently detected by an Apple XProtect update, is ad hoc signed. For command and control (C2), the implant polls the Telegram Bot API rather than a dedicated attacker-controlled server, routing operator communications through a legitimate platform to reduce the likelihood of network-level detection. Traffic is further protected by AES-GCM payload encryption and certificate pinning, which blocks standard proxy interception. The operator configuration, including the bot token and encryption key, is supplied at runtime rather than stored in the binary, and the implant actively redacts its bot token from runtime output to prevent recovery from logs or crash artifacts. Once active, the operator gains an interactive shell supporting process control, arbitrary command execution, and file exfiltration via Telegram, with evidence of a possible seventh command whose function could not be determined. Persistence is established through a LaunchAgent masquerading under Apple's namespace, and a power-management assertion prevents the host from sleeping during C2 polling. A gated Python stealer, deployed with its own runtime interpreter fetched at execution, harvests browser credentials, Terminal histories, application listings, a process snapshot, a system profile, and the macOS Keychain database. Most notably, the implant embeds 38 fabricated system-failure messages designed to mimic an LLM triage harness, with the aim of causing AI-assisted analysis pipelines to abort or refuse examination of the sample entirely.
Analyst Comment
macOS.Gaslight presents an immediate credential theft risk to any organisation running macOS endpoints. The stealer component targets browser credentials, Terminal histories, and the macOS Keychain database, with all collected data exfiltrated via Telegram. The Keychain database is particularly significant, as it stores saved passwords, certificates, and application tokens, meaning a successful compromise can expose credentials well beyond what the infected machine alone holds. Defenders should be aware of two distinct detection limitations at time of reporting: XProtect's current rule is hash-based and would not catch variants with modified hashes, and static engine coverage on VirusTotal was poor, suggesting limited third-party antivirus coverage independent of XProtect. Organisations should audit whether Telegram and other consumer messaging platforms are accessible from managed endpoints, since the implant routes all C2 and exfiltration through the Telegram Bot API, a channel that certificate pinning makes difficult to inspect in transit. Security teams should also consider whether outbound access to api.telegram.org is necessary from managed macOS devices and restrict it where it is not. Finally, security teams building or evaluating LLM-assisted analysis tooling should note that this sample deliberately attempts to manipulate AI triage pipelines through embedded fabricated system messages, a technique that is likely to mature as AI-assisted analysis becomes more common in security operations.
MITRE ATT&CK Techniques
Source Country
Korea, democratic people's republic of
Source Region
Asia
Story #1  |  June 23, 2026

2 macOS.Gaslight: DPRK-Linked Rust Implant Embeds Prompt Injection to Disrupt AI-Assisted Triage

▶ expand
Researchers analyzed macOS.Gaslight, a Rust-based macOS backdoor and infostealer assessed with high confidence to be linked to North Korea-aligned threat activity. The sample, first uploaded to VirusTotal on May 22, 2026 and subsequently detected by an Apple XProtect update, is ad hoc signed. For command and control (C2), the implant polls the Telegram Bot API rather than a dedicated attacker-controlled server, routing operator communications through a legitimate platform to reduce the likelihood of network-level detection. Traffic is further protected by AES-GCM payload encryption and certificate pinning, which blocks standard proxy interception. The operator configuration, including the bot token and encryption key, is supplied at runtime rather than stored in the binary, and the implant actively redacts its bot token from runtime output to prevent recovery from logs or crash artifacts. Once active, the operator gains an interactive shell supporting process control, arbitrary command execution, and file exfiltration via Telegram, with evidence of a possible seventh command whose function could not be determined. Persistence is established through a LaunchAgent masquerading under Apple's namespace, and a power-management assertion prevents the host from sleeping during C2 polling. A gated Python stealer, deployed with its own runtime interpreter fetched at execution, harvests browser credentials, Terminal histories, application listings, a process snapshot, a system profile, and the macOS Keychain database. Most notably, the implant embeds 38 fabricated system-failure messages designed to mimic an LLM triage harness, with the aim of causing AI-assisted analysis pipelines to abort or refuse examination of the sample entirely.
Analyst Comment
macOS.Gaslight presents an immediate credential theft risk to any organisation running macOS endpoints. The stealer component targets browser credentials, Terminal histories, and the macOS Keychain database, with all collected data exfiltrated via Telegram. The Keychain database is particularly significant, as it stores saved passwords, certificates, and application tokens, meaning a successful compromise can expose credentials well beyond what the infected machine alone holds. Defenders should be aware of two distinct detection limitations at time of reporting: XProtect's current rule is hash-based and would not catch variants with modified hashes, and static engine coverage on VirusTotal was poor, suggesting limited third-party antivirus coverage independent of XProtect. Organisations should audit whether Telegram and other consumer messaging platforms are accessible from managed endpoints, since the implant routes all C2 and exfiltration through the Telegram Bot API, a channel that certificate pinning makes difficult to inspect in transit. Security teams should also consider whether outbound access to api.telegram.org is necessary from managed macOS devices and restrict it where it is not. Finally, security teams building or evaluating LLM-assisted analysis tooling should note that this sample deliberately attempts to manipulate AI triage pipelines through embedded fabricated system messages, a technique that is likely to mature as AI-assisted analysis becomes more common in security operations.
MITRE ATT&CK Techniques
Source Country
Korea, democratic people's republic of
Source Region
Asia

FEATURED RESOURCES

December 24, 2025
Anomali Cyber Watch

Anomali Cyber Watch: Sample 3

LockBit 5.0 Ransomware Targets Windows, Linux, and VMware ESXi in Active Campaigns. Google Patches Actively Exploited Chrome Zero-Day CVE-2026-2441. Infostealer Targets OpenClaw Configuration Files to Capture Credentials and User Context. And more...
Read More
December 24, 2025
Anomali Cyber Watch

Anomali Cyber Watch: Sample

LockBit 5.0 Ransomware Targets Windows, Linux, and VMware ESXi in Active Campaigns. Google Patches Actively Exploited Chrome Zero-Day CVE-2026-2441. Infostealer Targets OpenClaw Configuration Files to Capture Credentials and User Context. And more...
Read More
December 24, 2025
Anomali Cyber Watch

Anomali Cyber Watch: Sample 2

LockBit 5.0 Ransomware Targets Windows, Linux, and VMware ESXi in Active Campaigns. Google Patches Actively Exploited Chrome Zero-Day CVE-2026-2441. Infostealer Targets OpenClaw Configuration Files to Capture Credentials and User Context. And more...
Read More
Explore All