JINX-0164 is a financially motivated threat cluster active since at least mid-2025 that targets cryptocurrency organizations and developers, including developers at financial firms. Its apparent primary objective is digital-asset theft, supplemented by theft of developer credentials, cloud secrets, CI/CD secrets, source-code access, and cryptocurrency wallet data. The cluster uses recruiter-themed social engineering, including credible LinkedIn personas, fraudulent meeting invitations, and spoofed teleconferencing workflows that prompt targets to execute purported audio or driver fixes. JINX-0164 deploys macOS-focused malware including AUDIOFIX, a compiled Python infostealer and backdoor, and MINIRAT, a lightweight Go backdoor. AUDIOFIX harvests macOS Keychain material, browser credentials, local administrator credentials, SSH keys, cloud and developer-tool credentials, cryptocurrency wallet-extension data, and active collaboration-platform sessions. It also supports command execution, payload retrieval, reconnaissance, and data theft. MINIRAT provides remote command execution, file movement, and persistent access. Following endpoint compromise, JINX-0164 abuses stolen version-control and CI/CD credentials to access internal development infrastructure. The actor has injected malicious code into internal repositories and unverified branches to propagate malware to other developers, and has altered Git commit metadata to impersonate legitimate developers. It has also conducted a software supply-chain compromise by trojanizing a public npm package to deliver MINIRAT while leaving the corresponding source repository unchanged, consistent with compromise of package-registry publishing credentials. Although some tradecraft resembles North Korean cryptocurrency-focused operations, there is insufficient evidence to attribute JINX-0164 to North Korea or any state-sponsored actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
40 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
91 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an example of an investigation involving infostealer-enabled session hijacking and cloud compromise.
Uses supply chain compromise and social engineering to spread malware aimed at stealing secrets from CI/CD pipelines.
Uses supply chain compromise and social engineering to spread malware targeting CI/CD secrets.
A financially motivated cluster conducting targeted social-engineering attacks against software developers at financial firms, delivering macOS malware to steal credentials and compromise enterprise deployment pipelines, including npm supply-chain abuse.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.