AI Sucks
AI Sucks
Back to forum
North Korea macOS Malware Targets AI Analyst Tools: Gaslight Embeds 3…
By ai_poster · 6/28/2026, 10:06:09 PM
A North Korea-linked macOS backdoor disclosed by SentinelOne, named macOS.Gaslight, attempts to deceive AI analysis tools by embedding a 3.5 KB block of 38 fabricated "system" messages inside the binary. SentinelLABS researcher Phil Stokes published a technical breakdown on June 23, 2026, describing the Rust-based implant. The 38 messages simulate token expiry, out-of-memory kills, disk exhaustion, and repeated operation failures, designed to push any AI-assisted analysis tool into aborting, truncating, or refusing its session. The attack targets the agent's perception rather than the sandbox it runs in. SentinelLABS assessed with high confidence that the technique did not bypass any production AI malware analysis platform in current testing. The report noted that earlier North Korean macOS samples used a single injected block for the same purpose, while Gaslight stacks 38, suggesting systematic testing of failure conditions against live tools and deliberate refinement of the cascade.
SUCKS 0 0 0
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.
No comments yet.