Malware sample whose metadata conflicts with claimed origin
Researchers recently disclosed Gaslight, a Rust-based macOS infostealer attributed with high confidence to North Korea-linked threat actors, which embeds prompt-injection payloads and cascading fake system-failure messages to sabotage LLM-assisted malware analysis, while communicating over a Telegram bot API channel. Files like this frequently carry origin metadata that contradicts their true provenance - compiler stamps, code-signing details, locale and language settings that do not match the developer or region the file claims to come from, a classic masquerading pattern (MITRE T1036.005). The Country of Origin module fingerprints these metadata artifacts to attribute the sample and flag inconsistencies with its claimed origin before it is trusted. The demo uses a benign sample whose metadata was deliberately altered, so it is safe to run in any environment.
Attack Technique
File origin attribution
MITRE ATT&CK
T1036.005 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗