Signal

New macOS backdoor uses prompt injection to evade AI triage while ClickFix attack spreads infostealer via DMGs

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-06-23 18:30 UTCUpdated 2026-06-24 14:00 UTC
rss
cveexploitsmalwarethreat_actorsincident_response
Trend in the last 24h
Current brief openSource links open
This current signal is open on the public brief with summary, metadata, source links, and full evidence. Pro adds compare-over-time, alerts, exports, and workflow.
No card needed for the free brief.
Evidence trail (top sources)
top sources (3 domains)domains are deduped. counts indicate coverage, not truth.
3 top sources shown
Infosecurity Magazine
infosecurity-magazine.com · infosecurity-magazine.com · 2026-06-24 14:00 UTC
SentinelOne Labs
sentinelone.com · sentinelone.com · 2026-06-23 21:59 UTC
BleepingComputer
bleepingcomputer.com · bleepingcomputer.com · 2026-06-23 18:30 UTC
Overview

Researchers have uncovered a North Korea-linked macOS backdoor named macOS.Gaslight that uses prompt injection to disrupt AI-assisted triage tools, evading detection.

Entities
macOS.GaslightClickFix
Score total
1.25
Momentum 24h
3
Posts
3
Origins
3
Source types
1
Duplicate ratio
0%
Why now
  • Recent discovery of macOS.Gaslight shows prompt injection as a new evasion tactic.
  • ClickFix campaign actively spreading info-stealers via DMGs demands immediate attention.
  • Apple's XProtect update triggered by these threats signals rising risk to macOS endpoints.
Why it matters
  • macOS threats are increasingly using AI evasion techniques, complicating detection and response.
  • Silent infection methods like mounting DMGs evade user awareness and traditional defenses.
  • North Korea-linked implants indicate ongoing state-sponsored targeting of macOS users.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • macOS.Gaslight backdoor uses prompt injection to evade AI triage tools
  • ClickFix campaign silently mounts malicious DMGs to deploy info-stealing malware on macOS
How sources frame it
  • Infosecurity Magazine: neutral
  • SentinelOne Labs: neutral
  • BleepingComputer: neutral
This briefing highlights advanced macOS threats using novel evasion techniques, underscoring the evolving risk landscape for Apple endpoint security.
All evidence
All evidence
Infosecurity Magazine
infosecurity-magazine.com · infosecurity-magazine.com · 2026-06-24 14:00 UTC
SentinelOne Labs
sentinelone.com · sentinelone.com · 2026-06-23 21:59 UTC
BleepingComputer
bleepingcomputer.com · bleepingcomputer.com · 2026-06-23 18:30 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 3Origin domains: 3Duplicates: -
Showing 3 / 0
Top publishers (this list)
  • infosecurity-magazine.com (1)
  • sentinelone.com (1)
  • bleepingcomputer.com (1)
Top origin domains (this list)
  • infosecurity-magazine.com (1)
  • sentinelone.com (1)
  • bleepingcomputer.com (1)