
North Korea's New macOS Backdoor Embeds Fake Error Messages to Fool AI Security Tools
SentinelOne researchers have identified Gaslight — a Rust-based macOS implant attributed to DPRK-linked actors that embeds 38 fabricated system messages designed to make AI-powered malware analyzers abort or refuse analysis. It steals browser data, Keychain credentials, and terminal history over an AES-GCM encrypted Telegram C2.










