Automatically translated.View original post

Beware of the new macOS malware, Gaslight.

Beware of the new macOS malware, Gaslight uses a Prompt Injection attack to fool AI on board.

According to a report by The Hacker News website, it specifically discusses the detection of a new malware aimed at attacking macOS users. A research team from SentinelOne, an expert company developing solutions for cyber protection, said that the malware was named Gaslight for deceiving its systems. The malware was designed to deceive the LLM (Large Language Model or Large Language Model) intelligence on macOS. In the Gaslight malware, fraudulent Prompt commands are embedded as misalerted messages. Missed more than 38 patterns to confuse the AI model's authentication mechanism until it malfunctioned and ultimately rejected malware file analysis. This malware is used as an intermediary to release data theft or Infostealer malware on the victim's machine. By examining the malware code, the research team found a large number of mood marks or Emoji in the comment section on the header of the code, showing that this malware was also created from LLM AI.

According to an in-depth review of the research team, the main architecture of the malware is a Bot interface API on the popular chat platform Telegram that acts as a C2 or Command and Control server, which logs in to check the Polling Loop to access intermediaries for sending commands like Interactive Shell and check the effect of using malware commands. There are 6 such commands:

Help, Enable Help (Help)

ID, used to check the malware identification number located on the victim's machine.

Shell, execute Shell commands through execvp

Kill, used to kill Process via PID

Upload, used to smuggle out files (Exfiltrate) through the "attach: / /" mechanism of the Telegram chat service.

Stop, use to suspend malware

The research team has said that the 7th expected command in the command name "focus" has also been detected, but it is not yet possible to confirm what the functionality of the command itself is; and for how to create malware persistence on the system, the malware modifies the LaunchAgent by adding "com.apple.system.services activity" to the .pist file.

The malware has also embedded Base-64 Encoding infostealer malware in a 6.6 KB Python script file. This malware has the ability to steal a lot of data, such as system data, such as local hardware and software, installed software lists, terminal command history data, database data (Database), data from many web browsers such as Chrome, Brave, Firefox, and Safari, etc. The stolen data is compressed into a file in the Zip file format (" Temp / collected_data.zip ") and then send the data to the Telegram bot.

# Trending # lemon 8 diary # macos # Gaslight # freedomhack

7/24 Edited to

... Read moreจากประสบการณ์การใช้งาน macOS ผมเคยได้ยินข่าวเกี่ยวกับมัลแวร์ที่ใช้งานแบบใหม่ ๆ แต่ Gaslight ถือเป็นกรณีที่น่าสนใจเพราะมันใช้ข้อได้เปรียบของ AI ที่ฝังในระบบมาหลอกลวงโดยตรง เทคนิคที่เรียกว่า Prompt Injection ทำให้โมเดล AI ของ macOS สับสนและไม่สามารถวิเคราะห์มัลแวร์ได้อย่างถูกต้อง ซึ่งเป็นช่องโหว่ที่ผู้ร้ายไซเบอร์ใช้ประโยชน์ได้อย่างชาญฉลาด พฤติกรรมของ Gaslight ที่ใช้ Telegram เป็น Command and Control (C2) ทำให้มันมีความสามารถในการรับคำสั่งและส่งข้อมูลกลับไปอย่างลับ ๆ ผ่านช่องทางที่แพร่หลายและตรวจสอบได้ยาก เช่น คำสั่งช่วยเหลือ, ตรวจสอบหมายเลขมัลแวร์, รันคำสั่งผ่าน shell, ฆ่าโปรเซส, อัปโหลดข้อมูล และคำสั่งหยุดการทำงาน ซึ่งก็แสดงให้เห็นว่ามัลแวร์นี้มีระบบควบคุมที่ซับซ้อนพอสมควร ผมลองสังเกตว่ามัลแวร์ฝัง Infostealer ที่เข้ารหัสด้วย Base-64 ในไฟล์ Python ที่มีขนาดเล็กแค่ 6.6 KB โดยมันสามารถดึงข้อมูลส่วนตัวจากระบบเช่น ฮาร์ดแวร์, ซอฟต์แวร์, ประวัติคำสั่ง Terminal, Keychain และข้อมูลจากเบราว์เซอร์ยอดนิยมอย่าง Chrome, Brave, Firefox และ Safari ด้วยวิธีการบีบอัดเป็นไฟล์ Zip ก่อนส่งผ่าน Telegram ซึ่งนี่เป็นการละเมิดความเป็นส่วนตัวอย่างรุนแรง ทางที่ดีที่สุดสำหรับผู้ใช้ macOS คือควรอัปเดตระบบและซอฟต์แวร์ป้องกันไวรัสอย่างสม่ำเสมอ และระวังการใช้งานโปรแกรมที่ไม่น่าไว้ใจ รวมถึงการสังเกตพฤติกรรมผิดปกติ เช่น เครื่องทำงานช้าหรือแปลก ๆ นอกจากนี้ ควรตรวจสอบการตั้งค่า LaunchAgent ที่อาจถูกแก้ไขและมีไฟล์ .plist ที่ผิดปกติ เพื่อป้องกันไม่ให้มัลแวร์สร้างความคงทนบนเครื่อง เทคนิคที่ Gaslight ใช้แสดงให้เห็นว่าวิธีการโจมตีโดยใช้ AI มาปรับแผนอีกขั้น ตอนนี้ผู้ใช้งาน macOS ควรตระหนักถึงภัยไซเบอร์ในรูปแบบใหม่ ๆ หมั่นติดตามข่าวสารและพูดคุยแลกเปลี่ยนข้อมูลกับผู้เชี่ยวชาญ เพื่อเป็นเกราะป้องกันตัวเองจากการโจมตีแบบนี้ในอนาคตได้ดีขึ้น