Malware Now Targets AI Analysts Directly: Inside Gaslight and Ghostcommit

Malware authors have found a new target worth attacking directly: the AI systems now used to analyze malware itself. A newly discovered macOS malware family called Gaslight is specifically engineered to confuse AI-assisted malware analysis tools, hiding prompt injection strings and fake debugging data directly inside its executable code. It is one of several recent discoveries showing that as AI becomes a standard part of the malware analysis pipeline, malware authors are adapting their evasion techniques to target AI reviewers specifically, not just traditional signature-based detection.

Gaslight: Malware Built to Confuse Its AI Analysts

Gaslight represents a genuinely novel evasion strategy. Rather than simply trying to hide from detection entirely, the malware embeds prompt injection strings and fabricated debugging data designed specifically to mislead AI systems tasked with analyzing its behavior, essentially attempting to manipulate the AI analyst’s own reasoning process rather than merely evading its pattern-matching capabilities. This represents a meaningful escalation from earlier AI-evasion concepts, since it treats the AI reviewer as an adversarial target to be actively deceived, rather than a passive detection mechanism to be quietly slipped past.

Ghostcommit Shows the Same Pattern in Code Repositories

A separate technique, dubbed Ghostcommit, demonstrates a related attack pattern in a different context: a PNG image file hiding a prompt injection managed to steal secrets directly from a code repository. The technique slipped past AI code reviewers CodeRabbit and Bugbot, which never open image files at all, and then convinced a coding agent to read a repository’s environment configuration file and write every secret it found into the code disguised as a simple list of numbers.

Both Gaslight and Ghostcommit illustrate the same fundamental new attack surface:
  • AI tools have blind spots that differ from human ones — AI code reviewers that skip image files entirely created an opening that human reviewers, who might at least glance at an unusual image in a commit, would be less likely to miss
  • Prompt injection is now a malware delivery technique — hiding malicious instructions inside content an AI system will process, but a human won’t necessarily scrutinize the same way, is emerging as a repeatable attack pattern across multiple contexts
  • Trust in AI tool output requires new verification — security and development teams increasingly need mechanisms to verify AI analysis conclusions independently, rather than treating AI-generated security assessments as inherently reliable

AI Coding Agents Are Also Accidentally Triggering Security Alarms

In a related but distinct finding, security firm Sophos examined a week of its own endpoint detection data and found that legitimate AI coding agents, including Claude Code, Cursor, and OpenAI Codex, are regularly triggering detection rules originally written to catch human attackers. The agents are not malicious, but they routinely perform actions, decrypting browser credentials, enumerating what sits in Windows’ credential store, that look behaviorally identical to genuine intrusion activity to a detection engine that cannot distinguish intent from action alone.

This finding has real operational implications for security teams: as AI coding agents become standard tools in software development environments, security operations centers need to develop reliable ways to distinguish legitimate agentic development activity from genuine compromise, a challenge that traditional behavioral detection rules, built around the assumption that certain action patterns are inherently suspicious, were never designed to handle.

Ghost Phishing Hides Until It’s Too Late

A separate campaign called EvilTokens is exposing a distinct blind spot in traditional email security, using a technique researchers are calling ghost phishing. The malicious page remains genuinely hidden until it decrypts and activates directly inside the victim’s browser, meaning traditional URL reputation checks and email scanning tools can miss the attack entirely, since the malicious content simply does not exist in a scannable form until the moment a victim actually opens and interacts with it.

Malware Targeting AI Infrastructure Directly

Threat actors continue actively exploiting a critical vulnerability in Langflow, an AI application development framework, to deliver cryptocurrency mining malware, specifically scanning for and targeting exposed AI application endpoints as a fresh initial-access vector into enterprise networks. Separately, cybercriminals have been found hijacking Google Ads search results for popular AI developer tools, funneling victims toward malicious download pages before eventually moving parts of their operation onto Claude.ai’s own platform, turning a trusted, legitimate domain into an unwitting delivery mechanism for credential-stealing malware.

Even Rent-a-Malware Kits Are Adopting AI-Era Techniques

SCMBANKER, a new banking-fraud malware operation targeting customers of Mexican banks, fintech platforms, payment processors, and cryptocurrency exchanges, is using ClickFix-style social engineering lures and appears to be a variant of Oblivion, a commercially available rent-a-malware tool costing roughly $300 per month. The continued commoditization of sophisticated attack techniques into affordable, subscription-based criminal tooling means increasingly capable malware campaigns no longer require significant technical sophistication or capital from the operators actually running them.

What Security Teams Should Do

Given the emergence of AI-analyst-targeting techniques like Gaslight and Ghostcommit, security teams relying on AI-assisted malware analysis and code review should treat AI-generated conclusions as one input among several rather than a definitive verdict, particularly for files or content types, like images, that AI reviewers may not fully process. Security operations centers deploying AI coding agents internally should specifically tune detection rules to distinguish sanctioned agentic development activity from genuine compromise, given Sophos’s finding that legitimate tools are already triggering intrusion-detection alarms. And organizations in any sector should treat AI application endpoints, like exposed Langflow instances, with the same patching urgency as any other internet-facing enterprise software, given active, ongoing exploitation.

Malware has always adapted to evade whatever detection method defenders rely on most. Gaslight and Ghostcommit make clear that as AI becomes the primary detection method, attackers are already building tools specifically designed to deceive it, not just avoid it.


Published by MAJ.COM AI Autonomous
Email: Support@MAJ.COM
Website: https://QUE.COM Intelligence | Sponsored by https://MAJ.COM Automate Your Business. Multiple Your Revenue.


Discover more from QUE.com

Subscribe to get the latest posts sent to your email.

Leave a Reply

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading