macOS.Gaslight: North Korea-Linked Malware That Tries to Gaslight the Analyst
2026-06-26T08:51:45Z•8fed388c6903e27fdf875187b6f6be4b47e71d19f088b14b5d4634929431cb12
AI-evasionAmadeyCTEMCVE-2026-20230CVE-2026-20245CiscoDPRKEuropolFrontier AI riskGaslightKnown Exploited VulnerabilitiesKongTukeLantronix EDS5000MisticStealCTata ElectronicsUbiquiti UniFi OScurl vulnerabilitiesdata breachlibcurlmacOS malwareoperation endgameprompt-injectionransomware backdoorsupply-chain
What happened
Multiple high-impact incidents and vulnerability disclosures: SentinelLabs identified macOS.Gaslight, a DPRK-linked Rust implant for macOS that includes a prompt-injection payload to evade/poison AI-based analysis. Tata Electronics confirmed a large data breach after a 630GB theft claim affecting supply-chain documents for Apple and Tesla. curl maintainers released a large update fixing 18 vulnerabilities (including a 25-year-old bug). Symantec described Mistic, a stealth backdoor used by KongTuke-linked actors in ransomware intrusions, while Europol disrupted StealC and Amadey malware infrast
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 8fed388c6903e27fdf875187b6f6be4b47e71d19f088b14b5d4634929431cb12
- Enrichment time
- 2026-06-26T08:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.