PULSE NAME
A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure
WHITE JINX-0164 AlienVault 2026-05-28 Modified: 2026-05-28
94
IOCs
HIGH VOLUME
JINX-0164, a financially motivated threat actor active since mid-2025, has been conducting sophisticated campaigns against cryptocurrency organizations. The actor employs LinkedIn-based social engineering, posing as recruiters or business partners to deliver custom macOS malware including AUDIOFIX (a Python-based infostealer and RAT) and MINIRAT (a lightweight Go backdoor). Their operations focus on compromising developer endpoints to steal cryptocurrency wallet credentials, cloud secrets, and GitHub tokens. The attackers then pivot to CI/CD infrastructure, injecting malicious code into repositories to enable lateral movement. In April 2026, they executed a supply chain attack by trojanizing the npm package @velora-dex/sdk. The group masks activity using VPN services and demonstrates advanced capabilities including credential harvesting from password managers, browser extensions, and development tools.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
AUDIOFIX MINIRAT
Indicators of Compromise (94)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 3318c614fa7d74b71c81f0e5532cc27e 2026-05-28
FileHash-MD5 425dbed05e53394a719c6e0986a9ce87 2026-05-28
FileHash-MD5 5fa825564b4ede126005a88ba9efbb54 2026-05-28
FileHash-MD5 7bd3201946ef8b8a836bc2f951923adc 2026-05-28
FileHash-MD5 860ef29773cf680ed765cb08ac3072cb 2026-05-28
FileHash-MD5 ce9da8845b153c5ba50281304b77969b 2026-05-28
FileHash-SHA1 0614fe623f6014bccae634e15e3c883a41aa89ee 2026-05-28
FileHash-SHA1 2e763321936858b8a566eaadcaf5a7ce064bbad0 2026-05-28
FileHash-SHA1 6ca184cb838a989220254ff1914313d774e65712 2026-05-28
FileHash-SHA1 d068b346169ced2ed677e1d4d75becf84829017f 2026-05-28
FileHash-SHA1 db077e20e429b93d9b1187cf09869544d83dbe02 2026-05-28
FileHash-SHA1 e581b38c6d4e659742839f3025a2add0a7e3fe60 2026-05-28
FileHash-SHA256 0a8ab3d16b12d3a453ee5a3208fe04744ad54514ef8ea27bb8fe32679efad270 2026-05-28
FileHash-SHA256 0b028b781950641818800fee2b4bf68e4ef2bcee53fe71a21755275ba108783d 2026-05-28
FileHash-SHA256 0b1a36a31b952341a534fe24890f1ed2921ee259773cff46e4f6273b8c4d5d21 2026-05-28
FileHash-SHA256 2a10ffe0367bb1b26ba2c3bc600892c21074725c0b8c9dc9161e6ceb33915460 2026-05-28
FileHash-SHA256 3e3901519c2305fbe9d5483b7234c25c6d2b562512916481d96f26b849c39fdb 2026-05-28
FileHash-SHA256 402625ec79e3573a80b6de9b33fc1e503e3c7803603cd958ddd515fb0549007c 2026-05-28
FileHash-SHA256 65cba741fe30fa4799fb9002ea8de6d96042a59159dd7c3419c766af24c835e6 2026-05-28
FileHash-SHA256 9c2ce925133a3bf5a924063bbef8df49918d5b7258695c1894cd18c75970157a 2026-05-28
FileHash-SHA256 a35d2b67fa478a7174e308b43ce30bf69b3bc6f44fa76197fdf95fc2fbc1cf5b 2026-05-28
FileHash-SHA256 b6cab0b3aa8e56e2427f486c74588d598ae58bb0cbc0eda6939fe171cb0aed17 2026-05-28
FileHash-SHA256 c6ef82d2864dfd26f117a1ef5602679153423f2742970a7949cec72722f0a01e 2026-05-28
FileHash-SHA256 d4e863f9818bfb2f1dd932df6441dff204e6142c3bdb55b298cb08dc7b6a0c62 2026-05-28
FileHash-SHA256 e8ee6f5145c9d503c5130bfc6585567f6e19d409158c3c0ca0b259f1875b15f4 2026-05-28
IPv4 185.100.85.250 2026-05-28
IPv4 185.100.85.98 2026-05-28
URL http://89.36.224.5/troubleshoot/mac/install.sh 2026-05-28
URL http://alibaba.xyz/minirat 2026-05-28
URL https://apple.driver-store.com/mac/arm/driver/coreaudiod 2026-05-28
URL https://apple.driver-store.com/mac/intel/driver/coreaudiod 2026-05-28
URL https://apple.driver-update.io/troubleshoot/mac/audio-issue-fix.sh 2026-05-28
URL https://learn.bitget-meeting.com/en-us/troubleshoot/microsoftteams/teams-on-mac/teams-audio-issue-mac 2026-05-28
URL https://www.iru.com/blog/minirat 2026-05-28
domain alibaba.xyz 2026-05-28
domain bitget-meeting.com 2026-05-28
domain byte-io.us 2026-05-28
domain cloud-sync.online 2026-05-28
domain datahub.ink 2026-05-28
domain driver-hub.net 2026-05-28
domain driver-store.com 2026-05-28
domain driver-update.io 2026-05-28
domain driver-updater.net 2026-05-28
domain drvstore.com 2026-05-28
domain live.ong 2026-05-28
domain live.org.mx 2026-05-28
domain slktest.live 2026-05-28
domain teamicrosoft.com 2026-05-28
domain teams.cam 2026-05-28
domain us03-slack.online 2026-05-28
hostname app.us03-slack.online 2026-05-28
hostname apple.driver-hub.net 2026-05-28
hostname apple.driver-store.com 2026-05-28
hostname apple.driver-update.io 2026-05-28
hostname apple.drvstore.com 2026-05-28
hostname learn.bitget-meeting.com 2026-05-28
hostname learn.live.ong 2026-05-28
hostname learn.retesta.live 2026-05-28
hostname learn.teamicrosoft.com 2026-05-28
hostname learn.teams.cam 2026-05-28
hostname learn.teams.us.org 2026-05-28
hostname live.teams.cam 2026-05-28
hostname login.bitget-meeting.com 2026-05-28
hostname login.live.ong 2026-05-28
hostname login.retesta.live 2026-05-28
hostname login.teamicrosoft.com 2026-05-28
hostname login.teams.cam 2026-05-28
hostname my-home-company-group.slktest.live 2026-05-28
hostname my-home-company-group.us03-slack.online 2026-05-28
hostname resource.bitget-meeting.com 2026-05-28
hostname resource.teamicrosoft.com 2026-05-28
hostname sitemaps.driver-store.com 2026-05-28
hostname team.live.us.org 2026-05-28
hostname teams.live.ong 2026-05-28
hostname teams.live.org.mx 2026-05-28
hostname teams.live.us.org 2026-05-28
hostname teams.retesta.live 2026-05-28
hostname windows.driver-hub.net 2026-05-28
hostname windows.driver-store.com 2026-05-28
hostname windows.driver-update.io 2026-05-28
hostname windows.drvstore.com 2026-05-28
hostname www.bitget-meeting.com 2026-05-28
hostname www.driver-hub.net 2026-05-28
hostname www.driver-store.com 2026-05-28
hostname www.driver-update.io 2026-05-28
hostname www.driver-updater.net 2026-05-28
hostname www.drvstore.com 2026-05-28
hostname www.live.ong 2026-05-28
hostname www.live.us.org 2026-05-28
hostname www.retesta.live 2026-05-28
hostname www.slktest.live 2026-05-28
hostname www.teamicrosoft.com 2026-05-28
hostname www.teams.cam 2026-05-28
hostname www.us03-slack.online 2026-05-28