VMTech
Discuss a project

Gaslight: macOS malware leverages prompt injection against AI-assisted analysis

Gaslight: macOS malware leverages prompt injection against AI-assisted analysis

Colleagues, please note: cybersecurity teams have identified a macOS stealer, Gaslight, that uses prompt injection to compromise AI assistants.

Briefly:
- SentinelOne: a Rust implant injects spoofed system prompts to cause LLM agents to abort or refuse analysis.
- C2 via Telegram bot: interactive shell with commands (exec, upload, kill, etc.) and data exfiltration.
- Embedded Python stealer collects terminal histories, profiles, Keychain and browser data; persistence via LaunchAgent.

Why this matters: it undermines trust in AI‑assisted triage — additional verification and validation of agent outputs are essential.

What additional controls should we impose on LLM assistants?

#cybersecurity #macOS #malware #AIsecurity

Open analytics
On the site 1 views
min read 1 28.06.2026
On Instagram 3 views
On Instagram 1 reach
Instagram

Gaslight: macOS malware leverages prompt injection against AI-assisted analysis

Open the post on Instagram ↗