A newly identified threat actor dubbed JINX-0164 is targeting cryptocurrency developers with sophisticated social engineering and custom macOS malware to steal digital assets and compromise internal development infrastructure.
Key Points
- Researchers at Wiz identified JINX-0164, a threat actor active since mid-2025 that uses recruitment-themed social engineering to target cryptocurrency organizations.
- Attackers use fake teleconference domains to trick victims into downloading the AUDIOFIX remote access trojan, which masquerades as a system audio driver.
- The malware steals sensitive data, including password manager credentials, SSH keys, cryptocurrency wallet addresses, and active session tokens from messaging platforms.
- JINX-0164 has successfully executed supply chain attacks, including the distribution of a Go-based backdoor called MiniRAT via a compromised npm package for VeloraDEX.
- The threat actor gains lateral movement by injecting payloads into code distribution systems and development infrastructure to modify source code and escalate access.