Living off the coding agent: Two tales of tunnels and LaunchAgents
ID: 5599041a-8ae2-54b9-9dcb-30f070c5c150
STIX ID: report--5599041a-8ae2-54b9-9dcb-30f070c5c150
Feed Name: Elastic Security Labs
This report analyzes a multi-day suspicious window on a macOS developer host where vendor-signed coding agents (Claude Code, Cursor) parented shells that performed credentialized HTTP to free tunnel brokers (localhost.run/lhr.life, trycloudflare, ngrok), established reverse tunnels (cloudflared), and installed LaunchAgent persistence; telemetry included malicious_file detections on tunnel binaries and production alerts such as "Persistence via GenAI Tool" and "Unusual Network Connection to Suspicious Web Service." The authors map the activity to MITRE-style techniques, highlight the detection challenges posed by trusted parent processes and dual-use services, and provide detection and prevention guidance emphasizing keeping high-severity outcomes noisy, naming destination classes early, and using session context rather than single-event reputation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
