Actor Profile

JINX-0164 is a previously undocumented threat actor with a financial motivation focused on digital asset theft. The group demonstrates technical sophistication through the development of custom macOS malware and operational tradecraft centered on social engineering via fake recruiter personas. Their targeting of cryptocurrency organizations and CI/CD infrastructure suggests a well-resourced adversary with specialized knowledge of both macOS environments and software development workflows. The actor's origin and broader affiliations remain unknown at this time.

TTPs (Tactics, Techniques, Procedures)

JINX-0164 employs sophisticated social engineering for initial access, likely leveraging T1566 (Phishing) through fake recruiter lures to establish trust with targets in cryptocurrency organizations. The deployment of custom macOS malware indicates capabilities in T1059 (Command and Scripting Interpreter) and T1204 (User Execution) to achieve code execution. The targeting of CI/CD infrastructure suggests potential use of T1195.001 (Supply Chain Compromise: Compromise Software Dependencies and Development Tools) or T1199 (Trusted Relationship) to gain access to development environments. The ultimate objective appears to be T1657 (Financial Theft) focused on cryptocurrency assets, potentially involving T1005 (Data from Local System) to locate and exfiltrate wallet credentials or private keys.

Targets & Patterns

JINX-0164 exclusively targets cryptocurrency organizations, demonstrating a clear financial motivation centered on digital asset theft. The use of fake recruiter lures suggests the actor targets individual employees within these organizations, likely focusing on developers, engineers, or other technical staff who would have access to critical systems. The specific targeting of CI/CD infrastructure indicates the actor seeks to compromise software development and deployment pipelines, which could provide persistent access to production environments, code repositories, or infrastructure hosting cryptocurrency wallets and transaction systems. This targeting pattern suggests the actor has conducted reconnaissance to identify high-value individuals with access to both development systems and potentially financial assets.

Historical Context

JINX-0164 is designated as a previously undocumented threat actor with no known historical campaigns or prior reporting. The combination of macOS-focused malware development and cryptocurrency targeting aligns with broader industry trends observed in North Korean-linked APT groups (such as Lazarus Group and BlueNoroff) and financially-motivated cybercrime actors, though no specific attribution link has been established. The use of fake recruiter lures as a social engineering vector has been observed in multiple cryptocurrency-focused campaigns over recent years, but JINX-0164's custom tooling and specific CI/CD targeting suggests this is a distinct operation rather than a continuation of known activity.

Defensive Recommendations

  • Implement strict code signing and verification policies for macOS endpoints, monitoring for execution of unsigned or ad-hoc signed binaries that may indicate custom malware deployment
  • Deploy enhanced monitoring on CI/CD infrastructure including audit logging of all pipeline modifications, credential access, and deployment activities to detect unauthorized access or tampering
  • Conduct security awareness training focused on recruiter impersonation tactics, emphasizing verification of recruiter identities through official company channels before engaging or opening attachments
  • Monitor for T1204.002 (Malicious File) execution patterns on macOS systems, particularly files delivered via messaging platforms or email from external recruiting contacts
  • Implement network segmentation to isolate CI/CD infrastructure from general corporate networks and cryptocurrency wallet/transaction systems to limit lateral movement opportunities