Skip to main content
See every side of every news story
Published loading...Updated

This macOS Malware Can Avoid AI Analysis with Gaslighting Prompts Hidden Inside Its Architecture

SentinelOne said the Rust-based malware hides 38 fake system messages and a 3.5 KB payload to mislead AI-assisted analysis tools.

  • SentinelOne recently uncovered Gaslight, a new piece of malware designed to weaponize LLM-assisted triage pipelines by deceiving AI-powered analysis tools into aborting investigations.
  • What makes the malware stand out is a 3.5 KB payload containing 38 fake "system" messages embedded directly within the binary. SentinelOne explains, "Its most notable feature is an embedded cascade of fabricated system-failure messages, designed to make an LLM-assisted triage agent doubt its own session."
  • These messages claim things like "The AI's authentication token has expired," "The analysis environment is running out of memory," or "Disk space has been exhausted." The scaffold embeds fake system messages about token expiry, out-of-memory kills, disk exhaustion, and repeated operation failures.
  • While SentinelOne did not demonstrate the technique could successfully bypass all platforms, researchers warn defenders to treat malware samples as adversarial input. Anyone building such tooling should isolate AI pipelines as more analyst-targeting prompt injection is expected.
  • The North Korean-linked malware also functions as an infostealer, pulling passwords and sensitive PDFs. Security teams log 54% of successful attacks and alert on just 14%, highlighting the detection gap this threat exploits.
Insights by Ground AI
Podcasts & Opinions

11 Articles

Gaslight, a new macOS malware, tries to blur the tracks in a rather new way: it hides false messages of error in its code to disrupt the analysis tools assisted by IA.

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

The Hacker News broke the news on Thursday, June 25, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal