Untangling a Linux Incident With an OpenAI Twist
Essential information
- Published
- 17/04/2026 16:19
- Modified
- 20/04/2026 11:22
- Source / Author
- AlienVault
- Confidence
- 100/100
- Report type(s)
- threat-report
- Labels / Tags
- codex ai credential theft cryptominer edr evasion linux compromise living-off-the-land monero mining multi-actor
- Tags
- 2026-04-17 codex ai credential-theft cryptominer edr evasion linux compromise living-off-the-land monero mining multi-actor
- Related entities
- 1 vulnerabilities (cve), 1 indicators, 1 observables, 20 techniques (mitre), 1 others
Description
A technology sector organization experienced a multi-actor compromise on a Linux endpoint where cryptominers were deployed and credential harvesting occurred. The incident became complex when the legitimate user attempted to troubleshoot suspected malicious activity using OpenAI's Codex AI agent while threat actors remained active on the system. The EDR agent was installed mid-compromise, limiting historical visibility. Codex-generated commands created investigative challenges as they mimicked attacker techniques, triggering security detections and complicating the distinction between legitimate troubleshooting and malicious activity. While Codex helped terminate some malicious processes, it failed to provide complete remediation, allowing threat actors to continue exfiltrating credentials, tokens, and cloud metadata through multiple persistence mechanisms.