JINX-0164JINX-0164

Also known as: JINX-0164

Known aliases
1

Profile

JINX-0164 is a financially motivated threat actor active since mid-2025, primarily targeting software developers through recruitment-themed social engineering to steal cryptocurrencies and conduct supply chain attacks. Their operations have focused on macOS devices, utilizing malware such as AUDIOFIX and MINIRAT, with a notable supply chain compromise involving the trojanization of an npm package. The actor employs a shell script for initial system profiling and payload delivery, often spoofing legitimate services like Microsoft Teams and cryptocurrency companies. JINX-0164's infrastructure includes numerous lookalike domains and utilizes VPN exit nodes for accessing victim systems.

Aliases· 1

JINX-0164

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
JINX-0126
Actor
UAC-0063
Actor
HexagonalRodent
Actor
INJ3CTOR3
Actor
UNC6426
Actor
TA406
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.