THREAT OPS › Threat News › Living off the coding agent: Two tales of tunnels and LaunchAgents
Living off the coding agent: Two tales of tunnels and LaunchAgents
<p>Coding agents such as Claude Code and Cursor are vendor-signed, used all day on developer laptops, and routinely open shells, call APIs, edit files, and install helpers. That makes GenAI-adjacent alerts challenging to investigate. The parent looks trusted, while the children can still look a lot like classic high-severity activity.</p> <p>This article walks through one of those windows. On a ma
MITRE ATT&CK techniques
- JavaScriptT1059.007
- Create or Modify System ProcessT1543
- KeychainT1555.001
- Application Layer ProtocolT1071
- Credentials from Password StoresT1555
- Exfiltration Over Web ServiceT1567
- Protocol TunnelingT1572
- Command and Scripting InterpreterT1059
- Web ServiceT1102
- Process DiscoveryT1057
- CredentialsT1589.001
- Launch AgentT1543.001
- Web ProtocolsT1071.001
- Ingress Tool TransferT1105
- Command and Scripting InterpreterAML.T0050
- Process DiscoveryAML.T0089
Indicators of compromise
- d335a47a04dde726897a2e753187e9f48fbf40616c48be3266954c7b9175a09esha256
- https://<id>.lhr.life"url
- https://<name>.trycloudflare.com/loginurl
- https://<name>.trycloudflare.com/url
- https://www.virustotal.com/gui/file/d335a47a04dde726897a2e753187e9f48fbf40616c48be3266954c7b9175a09eurl
- https://<id>.trycloudflare.com/loginurl
- api.trycloudflare.comdomain