Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors jinx-0164

Also known as: tracked as, Sleet

Description

JINX-0164 (also tracked as Sleet) emerges as a financially driven adversary that concentrates on the cryptocurrency sector, specifically targeting development teams and build infrastructures. Their techniques center on social engineering through LinkedIn recruiter personas, delivering malicious macOS installers that deploy RATs like AUDIOFIX—a Python-based infostealer—and MINIRAT—a lightweight Go backdoor. Once initial access is achieved, the attackers harvest credentials from password managers, browser extensions, and local development tools, then pivot into repository environments to inject malicious code or tamper with CI/CD pipelines. The group’s supply‑chain tactics were demonstrated in April 2026 when they compromised a legitimate npm package (@velora-dex/sdk) to propagate malware across the community. Their operations also make extensive use of VPN services for IP obfuscation, and they employ advanced lateral movement techniques such as token impersonation, process injection, and exploitation of Apple’s inter‑process communication mechanisms. This combination of endpoint compromise, credential harvesting, and supply‑chain infiltration makes JINX-0164 a high‑risk actor for any organization with a crypto development footprint.

Goals & Targeting

Targeted Sectors

Financial services
Critical infrastructure
Telecommunications
Manufacturing
Government
Gaming
Hospitality

Targeted Countries / Regions

US
RU
IR
MX
ES

AI Analysis

Grounded in web research
· 1 hour ago

Executive Summary

JINX-0164 is a financially motivated threat actor that has been exploiting cryptocurrency development environments since mid‑2025. Using recruiter-themed LinkedIn social engineering, the group deploys custom macOS RATs such as AUDIOFIX and MINIRAT to steal wallet credentials, cloud secrets, and GitHub tokens before pivoting into CI/CD pipelines for supply‑chain compromise. The actor’s operations are sophisticated, combining credential harvesting from password managers with covert command‑and‑control over VPN tunnels.

Goals & Targeting

JINX-0164 is motivated by monetary gain and selects victims that possess high-value digital assets or infrastructure capable of generating revenue. Their primary focus on cryptocurrency developers, wallets, exchanges, and cloud services allows them to capture wallet credentials, API tokens, and proprietary code that can be monetized directly (via theft) or leveraged to facilitate secondary attacks against the broader financial and critical‑infrastructure sectors listed in their target profile. The actor’s use of recruiter‑themed social engineering enables low‑cost initial access points into privileged development environments, while the subsequent pivot into CI/CD pipelines expands the attack surface for lateral movement.

Enhanced Description

Key Capabilities

  • LinkedIn recruiter-themed spear‑phishing
  • Custom macOS RAT deployment (AUDIOFIX, MINIRAT)
  • Credential harvesting from password managers and browser extensions
  • Supply‑chain compromise via malicious npm package injection
  • Lateral movement through CI/CD pipelines and repository tampering
  • Use of VPN for IP obfuscation and stealth
  • Advanced token impersonation and process injection on macOS and Windows

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Exfiltration
Command and Control

ATT&CK Techniques

T1566.001 – Phishing: Spear‑phishing attachment
T1566.002 – Phishing: Spear‑phishing link
T1134.003 – Make/Impersonate Token
T1134.004 – Parent PID Spoofing
T1105 – Ingress Tool Transfer
T1059.013 – Container CLI/API
T1060 – Registry Run Keys / Startup Folder
T1195 – Supply Chain Compromise
T1560.001 – Archive via Utility
T1132.001 – Standard Encoding
T1123 – Audio Capture
T1557 – Steal or Forge Kerberos Ticket (AS-REP, Silver Ticket)
T1086 – PowerShell
T1078 – Valid Accounts
T1055 – Process Injection
T1030 – Data Transfer Size Limits

Software / Tooling

AUDIOFIX
MINIRAT
@velora-dex/sdk (Trojanized npm package)
GitHub CLI tooling
VPN services used for C2 obfuscation

Campaigns & Victims

Since its first reported activity in mid‑2025, JINX-0164 has maintained an opportunistic pace of operations, targeting high‑value repositories and development machines across the United States, Russia, Iran, Mexico, and Spain. The actor typically begins with a recruiter‑themed phishing lure delivered via LinkedIn, then deploys macOS RATs to establish footholds. After credential harvesting, they pivot into CI/CD environments or inject malicious code into public npm packages, allowing widespread propagation with minimal effort. Notably, the April 2026 npm attack demonstrated their capability for large‑scale supply‑chain compromise and highlighted a pattern of leveraging third‑party package ecosystems as a fast delivery vector.

IOC Patterns

  • Spear‑phishing emails pretending to be recruiters or business partners
  • MacOS installer via .pkg or .dmg delivered through LinkedIn messages
  • C2 communication over VPN with obfuscated IP addresses
  • Malicious npm package distribution (@velora-dex/sdk)
  • Credential harvesting from password managers and browser extensions
  • Use of Go binaries or Python scripts for persistence (MINIRAT, AUDIOFIX)

Recommended Actions

  • Implement robust email filtering and threat intelligence feeds to block malicious LinkedIn-linked domains.
  • Enforce MFA on all developer accounts and limit external API keys to least‑privilege scopes.
  • Deploy endpoint detection & response solutions capable of detecting macOS RAT behaviors such as audio capture and process injection.
  • Conduct regular security reviews of repository commit histories and audit npm package dependencies for unauthorized changes.
  • Segment network zones between developer machines, CI/CD servers, and production environments to limit lateral movement.
  • Maintain a whitelist of approved third‑party packages and monitor pull request activity for anomalies.

Suggested Tags

APT
Financial Motivated
Cryptocurrency
Supply Chain Attack
macOS RAT
Spear-Phishing
Credential Theft

Confidence Assessment

The analysis is based on the SOC Prime article and Malpedia actor profile, both published in May‑August 2026. While these sources provide solid evidence of phishing via LinkedIn, macOS RAT deployment, and supply‑chain tactics, detailed timestamps for first/last seen are missing and some technique mappings rely on inference from related MITRE ATT&CK updates. Confidence is high regarding the attacker’s target profile, motivation, and core capabilities; moderate confidence for the full list of ATT&CK techniques and operational details, as newer activity may introduce additional methods not captured yet.

ATT&CK Techniques

Persistence
1 technique
Privilege Escalation
1 technique
16 techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.infosecurity-magazine.com — Cited by web research for: Sleet
  2. attack.mitre.org — Cited by web research for: T1518.002
  3. research.checkpoint.com — Cited by web research for: Telegram
  4. attack.mitre.org — Cited by web research for: Government
  5. https://malpedia.caad.fkie.fraunhofer.de/actor/jinx-0164 — Cited by AI analysis.
  6. https://www.socprime.com/threats/jinx-0164 — Cited by AI analysis.

Intel Summary

56

Techniques

48

Tools

0

Campaigns

86

IOCs

0

Observed Data

11

Tactics

Tags

Financial Targeting
Critical Infrastructure
Supply Chain Attack
Phishing
Backdoor / C2
Financial-Crime
Cryptocurrency-Targeted
Social-Engineering
APT
Supply-Chain-Attack
Financial Motivated
Cryptocurrency
macOS RAT
Spear-Phishing
Credential Theft

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
K
Confidence
55%
Added
May 28, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.