JINX-0164 Runs Fake-Recruiter Playbook Against Crypto Firms, Drops Custom macOS Malware

A newly catalogued threat actor is courting engineers at cryptocurrency companies with bogus job offers, then pivoting into CI/CD systems to siphon digital assets.

ThreatVectr Newsdesk· 2 min read
JINX-0164 Runs Fake-Recruiter Playbook Against Crypto Firms, Drops Custom macOS Malware
Share

A previously undocumented threat actor tracked as JINX-0164 is running a recruitment-themed social engineering campaign against cryptocurrency organizations, pairing it with bespoke macOS malware and unusually deep tradecraft against build pipelines.

The group surfaced in research published by Wiz, whose analysts describe operators fluent in the cadence of legitimate technical recruiting. Engineers at crypto firms are approached with what appears to be an interview process. Coding assignments and "environment setup" steps deliver the payload.

The end goal is asset theft.

JINX-0164 is not yet linked publicly to any known cluster, though the recruitment lure is a well-worn pattern in the crypto-targeting space, most notably associated with the DPRK-aligned activity tracked as Contagious Interview and the broader Lazarus umbrella. Wiz stops short of attribution.

What distinguishes this campaign is the targeting of CI/CD infrastructure once a developer's machine is compromised. Rather than smash-and-grab wallet draining, operators move toward build systems, signing keys, and pipeline secrets — the plumbing that can be abused to push malicious updates or quietly reroute funds at the protocol layer. That posture suggests an interest in supply-chain access, not just whatever sits in a single hot wallet.

The macOS payload is custom. Researchers note the malware is engineered specifically for the Apple developer environment common at crypto startups, with capabilities for credential harvesting, browser data theft, and persistence suited to engineers who routinely run unknown code as part of "take-home" interview tasks.

Victim count, ransom demands, and specific firm names are not part of this story; JINX-0164's model is theft, not extortion, and no leak site is associated with the group. Losses, where they occur, show up as on-chain drains rather than published victim lists.

Defensive guidance from the writeup leans operational. Treat unsolicited recruiter outreach that requires running code as hostile until proven otherwise. Isolate interview assignments to disposable VMs. Audit which developer endpoints can reach production CI/CD, and assume that an engineer's laptop is a path to signing infrastructure unless explicitly segmented.

The campaign sits inside a broader pattern that has dogged the crypto sector for at least three years: targeted human-layer compromise of developers, followed by lateral movement into the systems that actually move money. Earlier incidents involving fake job descriptions delivered via LinkedIn and Telegram have produced nine-figure losses at individual exchanges and bridge operators.

JINX-0164 appears to be the latest entrant working that seam. Whether the group is a standalone financially motivated crew, a contractor, or a rebrand of something already on analysts' boards is, for now, an open question.

Indicators of compromise and the full technical breakdown are in the Wiz research note.

© 2026 Threat Vectr