Also known as: tracked as, fractionators
JINX-0126 exploits publicly exposed PostgreSQL instances that are either misconfigured or protected by weak, guessable passwords. Once authenticated, the actor leverages the database’s COPY … FROM PROGRAM SQL command to execute arbitrary shell commands directly on the host machine. This technique bypasses traditional input sanitisation controls and provides immediate foothold. Post‑compromise, the adversary deploys a suite of lightweight, fileless binaries delivered through Linux memfd mechanisms. The payload chain begins with PG_MEM, a Go‑written tool that scans the system for competing miners and installs the cpu_hu binary. It also spawns another program called "postmaster", which masquerades as a PostgreSQL server in order to maintain persistence via cron jobs and create new high‑privilege local accounts. The ultimate goal is to run XMRig‑C3 miners invisibly; each infected host receives a unique mining worker ID and a distinct cryptographic hash for the binary, effectively eliminating file‑based detection by endpoint protection platforms. The actor also fetches fresh miner binaries directly from GitHub, ensuring that no static artefact stays on disk.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
JINX-0126 is a low‑but stealthy cryptojacking actor that abuses exposed PostgreSQL servers by abusing weak credentials and the SQL COPY ... FROM PROGRAM command to execute fileless miners. The campaign, first documented in August 2024, has compromised more than 1,500 databases worldwide and assigns unique mining worker IDs and binary hashes per victim to evade detection. The primary motive is financial gain via large‑scale XMRig-C3 cryptocurrency mining, with victims spanning multiple sectors including finance, healthcare, energy, and government.
Goals & Targeting
JINX-0126 operates with a primary financial incentive: to monetize compromised systems through anonymous cryptocurrency mining. By targeting misconfigured PostgreSQL databases—common in public‑cloud and remote‑desktop deployments— the actor can infiltrate high‑value enterprise environments across finance, energy, healthcare, manufacturing, gaming, transportation, and government sectors. The focus on Brazil (BR) and the United States (US) reflects both the prevalence of openly accessible Postgres services there and the large addressable market for cryptomining revenue.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since August 2024, JINX-0126 has conducted a large‑scale cryptomining operation that has compromised an estimated 1,500+ exposed PostgreSQL servers. Each victim receives a unique miner worker and binary hash, allowing the actor to evade detection by traditional file‑hash based security tools. The actors prefer a stealthy fileless execution model, leveraging Linux memfd and custom binaries that remain in memory, which has made traffic-based detection more difficult. Operations are sporadic but coordinated, focusing on servers with weak credentials; there is no evidence yet of lateral movement beyond the database host itself.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The intelligence is predominantly derived from a single, authoritative research report by Wiz dated March 2025 and corroborated by Aqua Security’s earlier detection in August 2024. While the technical details of the exploitation chain are clear and well‑documented, information on broader operational behaviour, long‑term threat actor organization, or additional assets beyond cryptomining is limited. Overall confidence in the core TTPs is high; however gaps remain regarding persistence mechanisms outside PostgreSQL, lateral movement capabilities, and potential future payload variations.
No campaigns linked yet.
No observed data linked yet.
7
Techniques
43
Tools
0
Campaigns
13
IOCs
0
Observed Data
1
Tactics