logo

JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware

ID: 23757af1-17b4-5fae-b3e1-0b918e6cf95c

STIX ID: report--23757af1-17b4-5fae-b3e1-0b918e6cf95c

Feed Name: The Hacker News

Threat Score
82/100

Date Published: 2026-05-28

Date Updated: 2026-05-28

Author: [email protected] (The Hacker News)

...
...

Wiz researchers attribute an active campaign since mid-2025 to a previously undocumented threat actor dubbed JINX-0164 that targets cryptocurrency developers and organizations using recruitment-themed social engineering and fake teleconference/driver domains to install custom macOS malware (a Python infostealer, AUDIOFIX RAT) and MiniRAT via a poisoned npm package, enabling credential theft, lateral movement into CI/CD and code distribution systems, source-code modification, and cryptocurrency theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.