• Latest
Mac malware campaign targets crypto coders — Arabian Post

Mac malware campaign targets crypto coders — Arabian Post

May 29, 2026

Lelaki dicekup PGA selepas edar pil kuda selama tiga tahun

June 23, 2026
Trump criticizes UK’s Starmer after resignation announcement

Trump criticizes UK’s Starmer after resignation announcement

June 23, 2026
Gaza surfers seek solace from war in the sea | Gaza

Gaza surfers seek solace from war in the sea | Gaza

June 23, 2026
Micic leads Hapoel Tel Aviv past Maccabi Tel Aviv in Finals Game 3 win

Micic leads Hapoel Tel Aviv past Maccabi Tel Aviv in Finals Game 3 win

June 23, 2026
‘So proud of him’: Singaporeans praise local uni-reject who delivered speech at Harvard Medical School

‘So proud of him’: Singaporeans praise local uni-reject who delivered speech at Harvard Medical School

June 23, 2026
(EDITORIAL from Korea JoongAng Daily on June 23)

(EDITORIAL from Korea JoongAng Daily on June 23)

June 23, 2026
Lucknow fire tragedy: SIT to probe incident; submit report within 7 days

Lucknow fire tragedy: SIT to probe incident; submit report within 7 days

June 23, 2026
Suspects identified in Salem Quick Stop shooting incident

Suspects identified in Salem Quick Stop shooting incident

June 23, 2026
President Trump signs two executive orders aimed at speeding the development of advanced quantum computers and mitigating the security threats they present (Amrith Ramkumar/Wall Street Journal)

President Trump signs two executive orders aimed at speeding the development of advanced quantum computers and mitigating the security threats they present (Amrith Ramkumar/Wall Street Journal)

June 23, 2026
FRA vs IRQ FIFA World Cup 2026 LIVE score: Kylian Mbappe and co. in search of their second win | Football

FRA vs IRQ FIFA World Cup 2026 LIVE score: Kylian Mbappe and co. in search of their second win | Football

June 23, 2026
FIFA World Cup 2026: ‘Tired’ Messi savours record night as Argentina march on

FIFA World Cup 2026: ‘Tired’ Messi savours record night as Argentina march on

June 23, 2026
Drugmakers yet to see gains from government’s minimum import price policy

Drugmakers yet to see gains from government’s minimum import price policy

June 23, 2026
Tuesday, June 23, 2026
  • About us
  • Advertise with us
  • Submit Articles
  • Privacy Policy
  • Contact us
Asia Today
No Result
View All Result
Subscribe
  • Login
  • Eastern Asia
    • China
    • Japan
    • Mongolia
    • North Korea
    • South Korea
  • South-eastern Asia
    • Brunei
    • Cambodia
    • Indonesia
    • Laos
    • Malaysia
    • Myanmar
    • Philippines
    • Singapore
    • Thailand
    • Timor Leste
    • Vietnam
  • Southern Asia
    • Afghanistan
    • Bangladesh
    • Bhutan
    • India
    • Iran
    • Maldives
    • Nepal
    • Pakistan
    • Sri Lanka
  • Central Asia
    • Kazakhstan
    • Kyrgyzstan
    • Tajikistan
    • Turkmenistan
    • Uzbekistan
  • Western Asia
    • Armenia
    • Azerbaijan
    • Bahrain
    • Cyprus
    • Georgia
    • Iraq
    • Israel
    • Jordan
    • Kuwait
    • Lebanon
    • Oman
    • Qatar
    • Saudi Arabia
    • State of Palestine
    • Syria
    • Turkey
    • United Arab Emirates
    • Yemen
  • More News
    • Opinion
    • Politics
    • Business
    • Entertainment
    • Fashion
    • Food
    • Health
    • Lifestyle
    • Science
    • Tech
    • Sports
  • Eastern Asia
    • China
    • Japan
    • Mongolia
    • North Korea
    • South Korea
  • South-eastern Asia
    • Brunei
    • Cambodia
    • Indonesia
    • Laos
    • Malaysia
    • Myanmar
    • Philippines
    • Singapore
    • Thailand
    • Timor Leste
    • Vietnam
  • Southern Asia
    • Afghanistan
    • Bangladesh
    • Bhutan
    • India
    • Iran
    • Maldives
    • Nepal
    • Pakistan
    • Sri Lanka
  • Central Asia
    • Kazakhstan
    • Kyrgyzstan
    • Tajikistan
    • Turkmenistan
    • Uzbekistan
  • Western Asia
    • Armenia
    • Azerbaijan
    • Bahrain
    • Cyprus
    • Georgia
    • Iraq
    • Israel
    • Jordan
    • Kuwait
    • Lebanon
    • Oman
    • Qatar
    • Saudi Arabia
    • State of Palestine
    • Syria
    • Turkey
    • United Arab Emirates
    • Yemen
  • More News
    • Opinion
    • Politics
    • Business
    • Entertainment
    • Fashion
    • Food
    • Health
    • Lifestyle
    • Science
    • Tech
    • Sports
No Result
View All Result
Morning News
No Result
View All Result
Home Western Asia United Arab Emirates

Mac malware campaign targets crypto coders — Arabian Post

by Asia Today Team
May 29, 2026
in United Arab Emirates
Reading Time: 3 mins read
21 0
A A
0
Mac malware campaign targets crypto coders — Arabian Post
25
SHARES
307
VIEWS
Share on FacebookShare on Twitter

READ ALSO

AS Watson Launches brand lab to Turn Retail Scale into a Data-driven Brand Growth Engine — Arabian Post

Apple Intel chip plan boosts US foundry push — Arabian Post


Cryptocurrency builders have change into the main focus of a brand new macOS-focused cyber marketing campaign that makes use of faux recruiter approaches, malicious assembly hyperlinks and compromised software program pipelines to steal digital belongings and unfold malware via trusted inner methods.

The exercise is being tracked as JINX-0164, a beforehand unreported financially motivated menace actor lively since at the least mid-2025. Investigators discovered that the group has focused cryptocurrency organisations by approaching builders and workers via credible LinkedIn profiles, then steering them in direction of bogus on-line assembly platforms or job-related technical duties that result in malware set up.

The marketing campaign marks a shift from standard credential theft in direction of deeper assaults on growth infrastructure. As soon as a developer’s workstation is compromised, the attacker seeks entry to inner repositories, construct methods and code distribution channels, turning the sufferer’s personal engineering atmosphere right into a path for wider an infection. At the least one intrusion unfolded over about two weeks, starting with social engineering and ending with malicious source-code modifications designed to compromise extra endpoints.

The malware on the centre of the marketing campaign is AUDIOFIX, a Python-based macOS stealer and distant entry trojan. It’s delivered via scripts hosted on spoofed infrastructure that mimics trusted expertise companies, together with faux Apple-related domains. The payload is constructed to run on each Intel and Apple Silicon machines, rising its usefulness in opposition to developer groups that rely closely on macOS laptops.

After execution, AUDIOFIX makes an attempt to assemble credentials from macOS Keychain recordsdata, browser shops, password managers, native administrator accounts, SSH keys, configuration recordsdata, shell historical past and cryptocurrency pockets information. It additionally targets periods from communications platforms akin to Slack, Discord and Telegram, giving the attacker potential entry to group discussions, engineering channels and operational particulars. Cloud secrets and techniques, together with credentials linked to AWS, Google Cloud, Azure and Cloudflare, are additionally among the many materials sought.

The attacker’s behaviour reveals a selected curiosity in software program growth pipelines reasonably than broad cloud exploitation. Though some cloud sign-in makes an attempt had been noticed, the first goal gave the impression to be the abuse of Git repositories and CI/CD methods. In a single case, the actor injected AUDIOFIX into inner repositories, altered committer names and e mail fields to impersonate different builders, pushed code on to predominant branches the place protections had been weak, and hijacked present branches when direct entry was unavailable.

This method will increase the danger of secondary infections as a result of workers who pull code or construct from compromised repositories could unknowingly execute the malware. It additionally creates a possible route into supply-chain assaults, the place malicious code will be distributed via respectable channels and seem to return from trusted inner groups.

JINX-0164 has additionally been linked to MiniRAT, a Go-based backdoor distributed earlier via a compromised model of the npm bundle @velora-dex/sdk, a toolkit related to decentralised finance exercise. That episode underlined the broader danger dealing with Web3 and crypto builders, who usually rely upon open-source packages, automated builds and fast deployment workflows.

The marketing campaign resembles techniques utilized by a number of North Korea-linked clusters which have focused cryptocurrency staff via faux jobs, coding assessments and video-call lures. Nevertheless, investigators haven’t established sufficient proof to hyperlink JINX-0164 to a state sponsor. The dearth of infrastructure overlap with publicly tracked teams has stored attribution cautious, despite the fact that the sector focus and social-engineering strategies are acquainted to menace hunters.

Using recruiter themes stays efficient as a result of builders are accustomed to technical screening, code challenges and on-line conferences. Attackers exploit that routine by presenting malicious downloads as assembly fixes, drivers or venture dependencies. The method is especially harmful in cryptocurrency corporations, the place developer machines could maintain pockets information, deployment keys, alternate credentials and entry to delicate repositories.

The findings add to rising concern over developer workstations as a part of the software program provide chain. Safety groups have historically targeted on cloud environments, manufacturing servers and perimeter controls, however the marketing campaign reveals how a single laptop computer can change into a bridge into supply code, secrets and techniques and launch methods. Sturdy department safety, verified commits, hardware-backed keys, endpoint monitoring, restricted token scopes and tighter assessment of CI/CD secrets and techniques have change into central defensive measures.

For cryptocurrency corporations, the fast danger isn’t restricted to stolen wallets. A compromised developer account can expose personal repositories, inner tooling, customer-facing code and bundle publishing rights. That mixture can enable attackers to maneuver from particular person theft to broader ecosystem compromise, particularly the place launch pipelines lack separation of duties or the place automated methods settle for code modifications with restricted scrutiny.



Source link

Tags: ArabiancampaigncoderscryptoMacmalwarePosttargets

Related Posts

AS Watson Launches brand lab to Turn Retail Scale into a Data-driven Brand Growth Engine — Arabian Post
United Arab Emirates

AS Watson Launches brand lab to Turn Retail Scale into a Data-driven Brand Growth Engine — Arabian Post

June 22, 2026
Apple Intel chip plan boosts US foundry push — Arabian Post
United Arab Emirates

Apple Intel chip plan boosts US foundry push — Arabian Post

June 20, 2026
Gumi sharpens XRP treasury push — Arabian Post
United Arab Emirates

Gumi sharpens XRP treasury push — Arabian Post

June 21, 2026
ADIA joins Corona Remedies block deal — Arabian Post
United Arab Emirates

ADIA joins Corona Remedies block deal — Arabian Post

June 22, 2026
Tehran tightens grip on Hormuz shipping — Arabian Post
United Arab Emirates

Tehran tightens grip on Hormuz shipping — Arabian Post

June 20, 2026
DIFC moves to tighten AI data rules — Arabian Post
United Arab Emirates

DIFC moves to tighten AI data rules — Arabian Post

June 19, 2026
Asia Today

Copyright © 2022 Asia Today.

Navigate Site

  • Disclaimer
  • Privacy Policy
  • Cookie Privacy Policy
  • DMCA
  • Terms and Conditions
  • Contact us

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Homepages
  • World
  • Eastern Asia
    • China
    • Japan
    • Mongolia
    • North Korea
    • South Korea
  • South-eastern Asia
    • Brunei
    • Cambodia
    • Indonesia
    • Laos
    • Malaysia
    • Myanmar
    • Philippines
    • Singapore
    • Thailand
    • Timor Leste
    • Vietnam
  • Southern Asia
    • Afghanistan
    • Sri Lanka
    • Bangladesh
    • Bhutan
    • India
    • Iran
    • Maldives
    • Nepal
    • Pakistan
    • Central Asia
    • Kazakhstan
    • Kyrgyzstan
    • Tajikistan
    • Turkmenistan
    • Uzbekistan
  • Western Asia
    • Armenia
    • Azerbaijan
    • Bahrain
    • Cyprus
    • Georgia
    • Iraq
    • Israel
    • Jordan
    • Kuwait
    • Lebanon
    • Oman
    • Qatar
    • Saudi Arabia
    • State of Palestine
    • Syria
    • Turkey
    • United Arab Emirates
    • Yemen
  • Opinion
  • Politics
  • Business
  • Entertainment
  • Fashion
  • Food
  • Health
  • Lifestyle
  • Science
  • Tech
  • Travel
  • Sports
  • About us
  • Advertise with us
  • Privacy Policy
  • Contact us
  • Support AsiaToday

Copyright © 2022 Asia Today.