JINX-0164 Threat Actor - Remove Spyware & Malware with SpyHunter - EnigmaSoft Ltd
Summary
This report describes JINX-0164, a previously undocumented threat actor targeting cryptocurrency organizations with recruitment-themed social engineering and custom macOS malware. The attackers use fake LinkedIn personas and fraudulent meeting setups to trick developers into installing malware. They then steal credentials, wallet data, and other sensitive information while moving laterally into development and CI/CD environments. The campaign also includes a compromised npm package and a backdoor used to upload files, run commands, and deploy additional payloads. The activity highlights supply chain risk and the need for stronger developer and endpoint security controls.
Classifications
industries
Entertainment
applications
Customer Service & Support
AskAI Classifications
Labels
Cybersecurity Software
Anti-Malware Software
SaaS Security
Linked Companies
EnigmaSoft
$1M to $5M