macOS.Gaslight: North Korea-Linked Malware That Tries to Gaslight the Analyst

2026-06-26T08:51:45Z8fed388c6903e27fdf875187b6f6be4b47e71d19f088b14b5d4634929431cb12
AI-evasionAmadeyCTEMCVE-2026-20230CVE-2026-20245CiscoDPRKEuropolFrontier AI riskGaslightKnown Exploited VulnerabilitiesKongTukeLantronix EDS5000MisticStealCTata ElectronicsUbiquiti UniFi OScurl vulnerabilitiesdata breachlibcurlmacOS malwareoperation endgameprompt-injectionransomware backdoorsupply-chain

What happened

Multiple high-impact incidents and vulnerability disclosures: SentinelLabs identified macOS.Gaslight, a DPRK-linked Rust implant for macOS that includes a prompt-injection payload to evade/poison AI-based analysis. Tata Electronics confirmed a large data breach after a 630GB theft claim affecting supply-chain documents for Apple and Tesla. curl maintainers released a large update fixing 18 vulnerabilities (including a 25-year-old bug). Symantec described Mistic, a stealth backdoor used by KongTuke-linked actors in ransomware intrusions, while Europol disrupted StealC and Amadey malware infrast

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
8fed388c6903e27fdf875187b6f6be4b47e71d19f088b14b5d4634929431cb12
Enrichment time
2026-06-26T08:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.