New Threat Actor Targets Crypto Firms’ Development Infrastructure
ID: 0a9bc776-69fd-5223-8afe-44a74f99d7fc
STIX ID: report--0a9bc776-69fd-5223-8afe-44a74f99d7fc
Feed Name: The Cyber Express
Threat Score
Researchers at Wiz identified JINX-0164, a financially motivated threat actor active since at least mid-2025, which conducts highly targeted LinkedIn-based social engineering against developers at cryptocurrency firms to deliver custom macOS malware; the actors harvest credentials, pivot from developer machines into source code, CI/CD pipelines, and cloud environments, and have executed at least one software supply-chain compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
