PULSE NAME
A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure
WHITE JINX-0164 AlienVault 2026-05-28 Modified: 2026-05-28
94
IOCs
HIGH VOLUME
JINX-0164, a financially motivated threat actor active since mid-2025, has been conducting sophisticated campaigns against cryptocurrency organizations. The actor employs LinkedIn-based social engineering, posing as recruiters or business partners to deliver custom macOS malware including AUDIOFIX (a Python-based infostealer and RAT) and MINIRAT (a lightweight Go backdoor). Their operations focus on compromising developer endpoints to steal cryptocurrency wallet credentials, cloud secrets, and GitHub tokens. The attackers then pivot to CI/CD infrastructure, injecting malicious code into repositories to enable lateral movement. In April 2026, they executed a supply chain attack by trojanizing the npm package @velora-dex/sdk. The group masks activity using VPN services and demonstrates advanced capabilities including credential harvesting from password managers, browser extensions, and development tools.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
AUDIOFIX MINIRAT
Indicators of Compromise (6 / 94 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 3318c614fa7d74b71c81f0e5532cc27e 2026-05-28
FileHash-MD5 425dbed05e53394a719c6e0986a9ce87 2026-05-28
FileHash-MD5 5fa825564b4ede126005a88ba9efbb54 2026-05-28
FileHash-MD5 7bd3201946ef8b8a836bc2f951923adc 2026-05-28
FileHash-MD5 860ef29773cf680ed765cb08ac3072cb 2026-05-28
FileHash-MD5 ce9da8845b153c5ba50281304b77969b 2026-05-28