{"id":8609,"date":"2026-06-26T16:27:02","date_gmt":"2026-06-26T16:27:02","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=8609"},"modified":"2026-06-26T16:27:02","modified_gmt":"2026-06-26T16:27:02","slug":"malware-authors-subvert-ai-detection-systems","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=8609","title":{"rendered":"Malware authors subvert AI detection systems"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p>Enterprises that have turned to AI in order to boost their security defenses may have to reconsider their approach.<\/p>\n<p>Malware containing code that commands LLM-assisted products to abort their analysis or refuse to implement it is already circulating, <a href=\"https:\/\/www.sentinelone.com\/labs\/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox\/\" target=\"_blank\" rel=\"noopener\">according to a post<\/a> from security company SentinelLabs.<\/p>\n<p>SentinelLabs thinks it knows who\u2019s responsible for the malware, which attacks MacOS systems. \u201cApple\u2019s XProtect detects the sample under the rule MACOS_BONZAI_COBUCH, and SentinelLabs associates the BONZAI signature family with North Korean threat activity,\u201d the company wrote.<\/p>\n<p>It\u2019s calling the malware macOS.Gaslight.<\/p>\n<p>This is not the first example of malware specifically targeting AI-generated analysis. As SentinelLabs noted, <a href=\"https:\/\/research.checkpoint.com\/2025\/ai-evasion-prompt-injection\/\">Checkpoint first documented such an approach<\/a> exactly a year ago. And Socket followed suit with <a href=\"https:\/\/socket.dev\/blog\/mini-shai-hulud-miasma-and-hades-worms-target-bioinformatics-and-mcp-developers-via-malicious\">a report of a payload<\/a> that also used code to evade detection by AI models.<\/p>\n<p>This new generation of threats was mentioned in the OPSWAT report, <a href=\"https:\/\/www.opswat.com\/resources\/reports\/ponemon-state-of-file-security\" target=\"_blank\" rel=\"noopener\">The State of File Security<\/a> and <a href=\"https:\/\/www.csoonline.com\/article\/4053107\/ai-prompt-injection-gets-real-with-macros-the-latest-hidden-threat.html\">cybersecurity experts are warning<\/a> that AI-supported protection is not always the answer.<\/p>\n<p>SentinelLabs would certainly agree with that view. \u201cAs <a href=\"https:\/\/www.sentinelone.com\/labs\/building-an-adversarial-consensus-engine-multi-agent-llms-for-automated-malware-analysis\/\" target=\"_blank\" rel=\"noopener\">LLM-assisted analysis<\/a> becomes routine, defenders should expect more samples built to exploit it,\u201d it wrote.<\/p>\n\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Enterprises that have turned to AI in order to boost their security defenses may have to reconsider their approach. Malware containing code that commands LLM-assisted products to abort their analysis or refuse to implement it is already circulating, according to a post from security company SentinelLabs. SentinelLabs thinks it knows who\u2019s responsible for the malware, [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":8610,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-8609","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8609"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8609"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8609\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/8610"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8609"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8609"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8609"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}