Skip to main content
← Back to Demos
Country of Origin intermediate · 15 min

Malware sample whose metadata conflicts with claimed origin

Researchers recently disclosed Gaslight, a Rust-based macOS infostealer attributed with high confidence to North Korea-linked threat actors, which embeds prompt-injection payloads and cascading fake system-failure messages to sabotage LLM-assisted malware analysis, while communicating over a Telegram bot API channel. Files like this frequently carry origin metadata that contradicts their true provenance - compiler stamps, code-signing details, locale and language settings that do not match the developer or region the file claims to come from, a classic masquerading pattern (MITRE T1036.005). The Country of Origin module fingerprints these metadata artifacts to attribute the sample and flag inconsistencies with its claimed origin before it is trusted. The demo uses a benign sample whose metadata was deliberately altered, so it is safe to run in any environment.

Attack Technique

File origin attribution

MITRE ATT&CK

T1036.005 ↗

Platforms

linux

File Types

.docx

MetaDefender Capabilities

Country of Origin

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---