AUTO-UPDATED

JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware

A newly identified threat actor dubbed JINX-0164 is targeting cryptocurrency developers with sophisticated social engineering and custom macOS malware to steal digital assets and compromise internal development infrastructure.

Key Points

  • Researchers at Wiz identified JINX-0164, a threat actor active since mid-2025 that uses recruitment-themed social engineering to target cryptocurrency organizations.
  • Attackers use fake teleconference domains to trick victims into downloading the AUDIOFIX remote access trojan, which masquerades as a system audio driver.
  • The malware steals sensitive data, including password manager credentials, SSH keys, cryptocurrency wallet addresses, and active session tokens from messaging platforms.
  • JINX-0164 has successfully executed supply chain attacks, including the distribution of a Go-based backdoor called MiniRAT via a compromised npm package for VeloraDEX.
  • The threat actor gains lateral movement by injecting payloads into code distribution systems and development infrastructure to modify source code and escalate access.

Why it Matters

This campaign highlights a significant risk to the software supply chain, as attackers are successfully infiltrating development environments to compromise cryptocurrency assets. By targeting developers through professional social engineering, these actors can bypass traditional security perimeters to gain deep access to sensitive internal systems.
Internet Published by info@thehackernews.com (The Hacker News)
Read original