Users seeking Claude installation assistance have fallen victim to a deceptive scheme orchestrated by cybercriminals This article explores agenticsora com loaderagent. .
Indicators of Compromise (IoCs):- Type Indicator Description Domain agenticsora[. ]com Delivery infrastructure Domain malwareaudit[. ]com Alternate loader delivery infrastructure URL hxxp://agenticsora[.
]com/curl?token Zsh loader endpoint URL hxxp://agenticsora[. ]com/dynamic?txd=token Stage 3 AppleScript delivery URL hxxp://agenticsora[. ]com/gate?build=txd&token=uploadid Chunked data upload endpoint URL hxxps://agenticsora[. ]com/loaderagent?token Mach-O RAT download endpoint URL hxxps://agenticsora[.
]com/loadercapture-agent?token Screen-capture helper download URL hxxps://agenticsora[. ]com/ledger?token Trojanised wallet payload URL hxxps://agenticsora[. ]com/ledgerlive?token Trojanised wallet payload URL hxxps://agenticsora[. ]com/trezor?token Trojanised wallet payload IP address 85.206.161[.
]241:8443 RAT command-and-control server IP address 103.216.221[. ]95 Operator panel IP recorded in Stage 3 beacon URL hxxps://main.sdhomeinspectors[. ]com/modules/wallets Ledger recovery-phrase collection endpoint URL hxxps://main.southcarolinacounselor[. ]com/modules/wallets Trezor recovery-phrase collection endpoint File artifact /tmp/macsynctoken.lock MacSync single-instance mutex File artifact /tmp/osalogging.zip Archive containing staged stolen data File artifact /tmp/sync[random] Collection staging directory File artifact /tmp/.kgrab.sh Keychain Safe Storage theft script File artifact /tmp/.kpwd Temporary captured password file File artifact ~/.zshrc Temporary curl and zsh persistence entry File artifact ~/.local/com.apple.
[8hex].hcpi Dropped RAT binary File artifact ~/.local/.mpwd Captured account password used by RAT File artifact ~/.local/com.apple. [8hex].capture.app Screen-capture helper File artifact ~/Library/LaunchAgents/com.apple. [8hex].hcpi.plist LaunchAgent persistence File artifact /tmp/com.apple.tcc.prompted TCC prompt tracking file File artifact /tmp/com.apple.tcc.result TCC permission result file Application artifact Applications/LedgerWallet.app Trojanised wallet application Application artifact Applications/LedgerLive.app Trojanised wallet application Application artifact Applications/Trezor Suite.app Trojanised wallet application Command artifact /usr/sbin/screencapture -x Silent screen capture from a non-Apple parent process SHA-256 3db8befc08dc02ab7a76b5193abd81653775e8f3ceac5864c7c2188b2dbd3c54 Dynamic AppleScript SHA-256 3ae26ed89d3a1a140edc89ca78513aba2895789ed0d0f64cad6605b6f2347c7e Universal Mach-O RAT SHA-256 78dea0693ac2d70bdf8be7588667a75910e43fd84397ad484e710e37369a30f7 Capture-agent bundle SHA-256 9c09c303fa058c2d3e179969bd58ca5523775ff2d310fb2f8266ac74cb21ee81 ScreenCap Mach-O SHA-256 071bd109208eb1080ef525b5be394244cec467c59ffef5b8782cfb5e4850401d Ledger Wallet trojan payload SHA-256 31566a1df7070f30cb990aa5eab310c1d4e0266c8776e9438138e5438ec1cff8 Ledger Live trojan payload SHA-256 230dff4bf9442a951dcd6898b2110924969a20668c20a43e3ceed6fcef65963e Trezor Suite trojan payload












