Our friends at SentinelLABS have analyzed a Rust macOS implant that embeds a 3.5 KB prompt-injection payload containing 38 fabricated “system” messages, designed to steer an LLM-assisted triage pipeline into aborting or refusing analysis. Command-and-control runs over a Telegram Bot API polling loop, with AES-GCM payloads over certificate-pinned TLS.
The implant self-redacts its Telegram bot token in its own runtime output, denying it to anyone who captures logs or crash artifacts. Analysts ha