This macOS malware can avoid AI analysis thanks to lighting prompts hidden in its architecture


  • SentinelOne discovered macOS “Gaslight” malware that uses rapid injection to mislead AI-assisted sorting tools during scanning.
  • Beyond the standard backdoor and infostealer capabilities, it embeds fake Markdown “system” messages to trick LLMs into disrupting the investigation.
  • Researchers warn defenders to treat malware samples as adversarial input and isolate AI pipelines, as rapid injections are expected to be more targeted by analysts.

We’ve seen rapid injections into websites and emails, but what about malware samples? Security researchers SentinelOne recently published a detailed report on a newly discovered macOS malware called Gaslight which, as the name suggests, attempts to trick AI-assisted sorting agents into stopping scanning.

The malware itself is nothing fancy: it infects the device by any means necessary (usually phishing and social engineering), connects to the infrastructure controlled by the attacker via Telegram, and then executes different commands such as profiling the device, executing arbitrary shell commands, stealing files, or terminating processes.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top