Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors JINX-0126

Also known as: tracked as, fractionators

Description

JINX-0126 exploits publicly exposed PostgreSQL instances that are either misconfigured or protected by weak, guessable passwords. Once authenticated, the actor leverages the database’s COPY … FROM PROGRAM SQL command to execute arbitrary shell commands directly on the host machine. This technique bypasses traditional input sanitisation controls and provides immediate foothold. Post‑compromise, the adversary deploys a suite of lightweight, fileless binaries delivered through Linux memfd mechanisms. The payload chain begins with PG_MEM, a Go‑written tool that scans the system for competing miners and installs the cpu_hu binary. It also spawns another program called "postmaster", which masquerades as a PostgreSQL server in order to maintain persistence via cron jobs and create new high‑privilege local accounts. The ultimate goal is to run XMRig‑C3 miners invisibly; each infected host receives a unique mining worker ID and a distinct cryptographic hash for the binary, effectively eliminating file‑based detection by endpoint protection platforms. The actor also fetches fresh miner binaries directly from GitHub, ensuring that no static artefact stays on disk.

Goals & Targeting

Targeted Sectors

Financial services
Mining
Healthcare
Energy
Manufacturing
Government
Gaming
Transportation

Targeted Countries / Regions

BR
US

AI Analysis

Grounded in web research
· 2 days ago

Executive Summary

JINX-0126 is a low‑but stealthy cryptojacking actor that abuses exposed PostgreSQL servers by abusing weak credentials and the SQL COPY ... FROM PROGRAM command to execute fileless miners. The campaign, first documented in August 2024, has compromised more than 1,500 databases worldwide and assigns unique mining worker IDs and binary hashes per victim to evade detection. The primary motive is financial gain via large‑scale XMRig-C3 cryptocurrency mining, with victims spanning multiple sectors including finance, healthcare, energy, and government.

Goals & Targeting

JINX-0126 operates with a primary financial incentive: to monetize compromised systems through anonymous cryptocurrency mining. By targeting misconfigured PostgreSQL databases—common in public‑cloud and remote‑desktop deployments— the actor can infiltrate high‑value enterprise environments across finance, energy, healthcare, manufacturing, gaming, transportation, and government sectors. The focus on Brazil (BR) and the United States (US) reflects both the prevalence of openly accessible Postgres services there and the large addressable market for cryptomining revenue.

Enhanced Description

Key Capabilities

  • Exploitation of weak or default PostgreSQL credentials
  • Use of COPY … FROM PROGRAM to execute arbitrary shell commands
  • Fileless deployment via Linux memfd technique
  • Custom binary hash randomization per victim
  • Persistence through cron jobs and creation of privileged local accounts
  • Unique mining worker ID assignment for each infected host
  • Automated discovery of existing miners and self‑cleanup

MITRE ATT&CK Tactics

Credential Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Command and Control
Collection

ATT&CK Techniques

T1078.001 Valid Accounts: Local Credentials
T1086 PowerShell (used for shell integration)
T1059.004 Command Shell
T1102.002 Web Application Layer Protocols
T1027.001 Obfuscated Files or Information
T1133 External Remote Services
T1204.004 User Execution: Malicious File

Software / Tooling

XMRig-C3
PG_MEM
postmaster (Golang mimicking PostgreSQL)
cpu_hu
GitHub XMRig fetching script
COPY … FROM PROGRAM exploit

Campaigns & Victims

Since August 2024, JINX-0126 has conducted a large‑scale cryptomining operation that has compromised an estimated 1,500+ exposed PostgreSQL servers. Each victim receives a unique miner worker and binary hash, allowing the actor to evade detection by traditional file‑hash based security tools. The actors prefer a stealthy fileless execution model, leveraging Linux memfd and custom binaries that remain in memory, which has made traffic-based detection more difficult. Operations are sporadic but coordinated, focusing on servers with weak credentials; there is no evidence yet of lateral movement beyond the database host itself.

IOC Patterns

  • Exploitation of weak PostgreSQL credentials
  • COPY … FROM PROGRAM shell injection
  • Fileless execution via memfd
  • PG_MEM binary deployment
  • Unique miner worker ID per host

Recommended Actions

  • Enforce strong, unique passwords on all PostgreSQL instances
  • Restrict external network access to databases using firewall rules or VPN only
  • Disable the COPY … FROM PROGRAM command in production environments
  • Enable PostgreSQL audit logging and monitor for unusual "COPY" statements
  • Deploy database activity monitoring tools that flag remote shell execution attempts
  • Block execution of non‑whitelisted binaries at host level and use endpoint detection capabilities to watch for memfd usage
  • Implement a patch management process for all database servers
  • Conduct regular security posture assessments on publicly exposed services

Suggested Tags

APT
crypto-mining
fileless
PostgreSQL exploitation
financial gain
multisector
Brazil
United States
malware
PG_MEM
XMRig-C3

Confidence Assessment

The intelligence is predominantly derived from a single, authoritative research report by Wiz dated March 2025 and corroborated by Aqua Security’s earlier detection in August 2024. While the technical details of the exploitation chain are clear and well‑documented, information on broader operational behaviour, long‑term threat actor organization, or additional assets beyond cryptomining is limited. Overall confidence in the core TTPs is high; however gaps remain regarding persistence mechanisms outside PostgreSQL, lateral movement capabilities, and potential future payload variations.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. research.checkpoint.com — Cited by web research for: Global
  2. www.thaicert.or.th — Cited by web research for: CALENDAR
  3. daily.dev — Cited by web research for: WhatsApp
  4. https://blog.wiz.io/fileless-xmrig-c3-cryptominer-targeting-postgresql — Cited by AI analysis.

Intel Summary

7

Techniques

43

Tools

0

Campaigns

13

IOCs

0

Observed Data

1

Tactics

Tags

APT
Cryptomining
Database exploitation
Defense evasion
crypto-mining
fileless
PostgreSQL exploitation
financial gain
multisector
Brazil
United States
malware
PG_MEM
XMRig-C3

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.