INTEL_REPORT
SentinelOne Labs · published 6/23/2026, 9:59:42 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox DPRK-linked implant embeds 38 fabricated system messages that spoof an LLM triage harness, hiding a credential stealer and Telegram C2 underneath. Executive Summary SentinelLABS has analyzed a Rust macOS implant that embeds a 3.5 KB prompt-injection payload of 38 fabricated “system” messages, built to steer an LLM-assisted triage pipeline into aborting or refusing its analysis. Command-and…
https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox
sha256:7cb91a11b86dfdcaf1afd5139808541cdddf6edaf70a316a9fffbf48c7da35f6
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
| Type | Value | Link |
|---|---|---|
| domain | com.apple | Open → |
| domain | login.keychain | Open → |
| sha1 | 5555494492fc075f441637fb9d894913dde3a2ea | Open → |
| sha256 | 6328567511d88fdc2ae0939c5ef17b7a63d2a833881900de018a4f12f4982525 | Open → |
| sha256 | 77b4fd46994992f0e57302cfe76ed23c0d90101381d2b89fc2ddf5c4536e77ca | Open → |
| sha256 | b3c56d689414343589f38394d19ba2fe9a518133281200faa0556ba4e4136394 | Open → |
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| sha256 | baabf249c77bc54c54ab0e66e15af798bd28aa5b4683554456a8b73ab8741239 | Open → |
| domain | macos.gaslight | Open → |
| domain | com.apple.system.services.activity | Open → |