macOS malware spreads via X ads and AI‑evasive Gaslight strain uncovered
Security researchers reported that cybercriminals exploited a verified X account to run paid advertisements promoting a counterfeit version of the DynamicLake app, which mimics iPhone’s Dynamic Island on macOS. The ads redirected users to a look‑alike domain that instructed them to run a Terminal command, installing a malicious agent on their machines. Jamf Threat Labs disclosed the campaign, noting it leveraged the “ClickFix” social‑engineering technique to bypass X’s ad‑scanning safeguards and reach thousands of users.
Separately, SentinelOne identified a new macOS malware family called Gaslight that specifically targets AI‑based detection tools. The code injects dozens of false system messages to confuse and abort automated analyses, while also stealing browser credentials and keychain data. Experts warned that the tactic marks a shift toward malware designed to deceive artificial‑intelligence defenses, raising concerns about the security of increasingly automated cyber‑defense pipelines.