Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Gaslight

Gaslight

TLP:CLEAR
Family

AI Analysis

No AI analysis yet.

Description

According to SentinelLabs, Gaslight is a DPRK-aligned macOS backdoor and infostealer written in Rust that communicates over the Telegram Bot API, using AES-GCM encryption layered on certificate-pinned TLS. The implant provides an interactive remote shell with generic capabilities for command execution, file exfiltration, process management, and configuration-driven persistence, and it can stage a Python-based stealer via a bundled installer that fetches a standalone CPython runtime at execution time. It collects browser data, system and process information, and keychain contents, packaging and uploading them through the same hardened command-and-control channel. A distinctive characteristic is its embedded multi-message prompt-injection payload designed to manipulate LLM-assisted analysis pipelines, along with runtime self-redaction of its bot token to prevent credential leakage in logs or crash artifacts.

Details

Type
Unknown
Platforms
Macos
Confidence
80%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.