JINX-0164
2026-05-27 • Wiz • Commit to Compromise: A New Threat Actor Targetin…
Wiz's Customer Incident Response Team first identified and named JINX-0164 in a report published in late May 2026, describing it as a previously unreported, financially motivated cluster active since at least mid-2025, targeting developers and organizations across the cryptocurrency industry, including exchanges, DeFi protocol teams, and blockchain tooling firms. Operators build credible LinkedIn personas posing as recruiters, investors, or business contacts, then lure victims into virtual meetings on spoofed conferencing sites where a staged technical problem prompts download of a disguised fix, delivering custom macOS malware: a Python-based infostealer and remote-access tool harvesting browser and desktop cryptocurrency wallet data, credentials, SSH keys, cloud tokens, and messaging-app data, plus a lightweight backdoor. In April 2026 the group also trojanized a popular cryptocurrency SDK package on a public package registry to distribute the backdoor, showing a supply-chain capability alongside its social-engineering operations, with stolen developer credentials used to move laterally into internal code repositories and CI/CD pipelines. Researchers found tactical similarities to other North Korea-linked clusters but no confirmed infrastructure overlap; a later report separately described the group as North Korea-linked.
-
34
Related Actors
-
2
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster