North Korea-Linked macOS Backdoor Uses Prompt Injection to Bypass AI Triage Tools (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- Over 38 fake system messages embedded to subvert AI triage.
- Steals browser data, keychain, terminal histories, app lists.
- Uses Telegram Bot API with certificate pinning for C2.
"SentinelLabs identified a macOS backdoor, tracked as macOS.Gaslight, linked to North Korea. The Rust-based implant includes 38 fabricated system messages designed to trick AI triage tools into aborting analysis. It functions as an infostealer, exfiltrating browser data, terminal histories, and keychain contents via Telegram Bot API with certificate pinning."
no comments yet.