This macOS malware may bypass AI analysis with lighting messages hidden within its architecture



  • SentinelOne discovered “Gaslight” malware for macOS that uses rapid injection to trick AI-assisted classification tools during analysis.
  • Beyond standard backdoor and information theft capabilities, it incorporates fake Markdown “system” messages to trick LLMs into stopping the investigation.
  • Researchers warn defenders to treat malware samples as adversarial inputs and isolate AI channels as faster injection targeting analysts is expected.

We’ve seen rapid injections into websites and emails, but what about malware samples? Security researchers SentinelOne recently published a detailed report on a newly discovered piece of macOS malware called Gaslight that, as its name suggests, attempts to use AI-assisted classification agents to stop scanning.

The malware itself is nothing out of the ordinary: it infects the device by any means necessary (usually phishing and social engineering), connects to the attacker-controlled infrastructure via Telegram, and then executes different commands, such as profiling the device, executing arbitrary shell commands, stealing files, or killing processes.

Leave a Comment

Your email address will not be published. Required fields are marked *