news.mlab.sh
Back to the feed
threat-intel

JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware

High
Summary

A previously undocumented threat actor, dubbed JINX-0164, is targeting cryptocurrency firms through sophisticated social engineering tactics and bespoke macOS malware to steal digital assets. The campaign involves luring victims with fake recruiter opportunities, deploying a macOS infostealer named AUDIOFIX, and potentially leveraging supply chain attacks. The activity is motivated by financial gain and shares similarities with North Korean APT groups.

The JINX-0164 campaign began at least mid-2025 and focuses on cryptocurrency organizations, specifically targeting developers and their CI/CD infrastructure. The threat actor employs recruitment-themed social engineering, leveraging credible LinkedIn profiles to initiate contact and schedule virtual meetings. These meetings then lead victims to malicious domains masquerading as teleconference providers, prompting them to download and execute a macOS infostealer, AUDIOFIX. This malware steals sensitive data including credentials, SSH keys, and cryptocurrency wallet information, and facilitates lateral movement within the compromised network. The group also utilizes MiniRAT, a Go-based backdoor, which was initially distributed through a compromised npm package, highlighting a potential supply chain vulnerability. While no direct links to North Korean APT groups have been established, the tactics and spoofing domains employed bear resemblance to those used by groups like BlueNoroff and UNC1069.

Read the full article at The Hacker News