PULSE NAME
A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure
WHITE JINX-0164 AlienVault 2026-05-28 Modified: 2026-05-28
94
IOCs
HIGH VOLUME
JINX-0164, a financially motivated threat actor active since mid-2025, has been conducting sophisticated campaigns against cryptocurrency organizations. The actor employs LinkedIn-based social engineering, posing as recruiters or business partners to deliver custom macOS malware including AUDIOFIX (a Python-based infostealer and RAT) and MINIRAT (a lightweight Go backdoor). Their operations focus on compromising developer endpoints to steal cryptocurrency wallet credentials, cloud secrets, and GitHub tokens. The attackers then pivot to CI/CD infrastructure, injecting malicious code into repositories to enable lateral movement. In April 2026, they executed a supply chain attack by trojanizing the npm package @velora-dex/sdk. The group masks activity using VPN services and demonstrates advanced capabilities including credential harvesting from password managers, browser extensions, and development tools.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
AUDIOFIX MINIRAT
Indicators of Compromise (6 / 94 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 0614fe623f6014bccae634e15e3c883a41aa89ee 2026-05-28
FileHash-SHA1 2e763321936858b8a566eaadcaf5a7ce064bbad0 2026-05-28
FileHash-SHA1 6ca184cb838a989220254ff1914313d774e65712 2026-05-28
FileHash-SHA1 d068b346169ced2ed677e1d4d75becf84829017f 2026-05-28
FileHash-SHA1 db077e20e429b93d9b1187cf09869544d83dbe02 2026-05-28
FileHash-SHA1 e581b38c6d4e659742839f3025a2add0a7e3fe60 2026-05-28