This macOS malware can evade AI analysis with gaslighting prompts hidden in its architecture


  • SentinelOne exposed macOS malware “Gaslight” that uses rapid injection to mislead AI-assisted triage tools during analysis
  • In addition to standard backdoor and infostealer features, it embeds fake Markdown “system” messages to trick LLMs into stopping investigations
  • Researchers warn defenders to treat malware samples as adversarial input and isolate AI pipelines as more analyst-targeted prompt injection is expected

We’ve seen quick injection into websites and emails, but what about – malware samples? Security researchers SentinelOne recently published an in-depth report on a newly exposed piece of macOS malware called Gaslight that, as the name suggests, attempts to facilitate AI-assisted triage agents to stop the analysis.

The malware itself is nothing out of the ordinary: it infects the device by the necessary means (usually phishing and social engineering), connects to attacker-controlled infrastructure via Telegram, and then executes various commands such as profiling the device, running arbitrary shell commands, stealing files or terminating processes.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top