• Latest
Mac malware campaign targets crypto coders — Arabian Post

Mac malware campaign targets crypto coders — Arabian Post

May 29, 2026
Kurikulum memandu perlu selari teknologi moden

Kurikulum memandu perlu selari teknologi moden

May 30, 2026
Senate flood control scam hearings to resume on June 4

Senate flood control scam hearings to resume on June 4

May 30, 2026
For the first time, a kosher restaurant has won a Michelin star

For the first time, a kosher restaurant has won a Michelin star

May 30, 2026
UP Vigilance teams arrest four in anti-corruption traps across Baghpat, Hapur, Kannauj

UP Vigilance teams arrest four in anti-corruption traps across Baghpat, Hapur, Kannauj

May 30, 2026
Microsoft faces backlash after a blog post implied criminal referral and legal action against security researcher Nightmare Eclipse over public bug disclosures (Lorenzo Franceschi-Bicchierai/TechCrunch)

Microsoft faces backlash after a blog post implied criminal referral and legal action against security researcher Nightmare Eclipse over public bug disclosures (Lorenzo Franceschi-Bicchierai/TechCrunch)

May 30, 2026
Molecule glue drugs shake up cancer care, draw big money

Molecule glue drugs shake up cancer care, draw big money

May 30, 2026
Salamé alerte l’Unesco face aux menaces des frappes israéliennes

Salamé alerte l’Unesco face aux menaces des frappes israéliennes

May 30, 2026
Norway Chess: Will Gukesh’s Birthday Spark A Comeback?

Norway Chess: Will Gukesh’s Birthday Spark A Comeback?

May 30, 2026
Ananya Panday and classical dance in the age of virality

Ananya Panday and classical dance in the age of virality

May 30, 2026
Israel-Lebanon negotiations will proceed at Pentagon despite renewed violence

Israel-Lebanon negotiations will proceed at Pentagon despite renewed violence

May 29, 2026
Wife of local singer shot to death « RAWA News

Wife of local singer shot to death « RAWA News

May 30, 2026
‘Predator’ staying at an asylum seeker hotel sexually assaulted two women after prowling the streets looking for ‘good time’

‘Predator’ staying at an asylum seeker hotel sexually assaulted two women after prowling the streets looking for ‘good time’

May 29, 2026
Saturday, May 30, 2026
  • About us
  • Advertise with us
  • Submit Articles
  • Privacy Policy
  • Contact us
Asia Today
No Result
View All Result
Subscribe
  • Login
  • Eastern Asia
    • China
    • Japan
    • Mongolia
    • North Korea
    • South Korea
  • South-eastern Asia
    • Brunei
    • Cambodia
    • Indonesia
    • Laos
    • Malaysia
    • Myanmar
    • Philippines
    • Singapore
    • Thailand
    • Timor Leste
    • Vietnam
  • Southern Asia
    • Afghanistan
    • Bangladesh
    • Bhutan
    • India
    • Iran
    • Maldives
    • Nepal
    • Pakistan
    • Sri Lanka
  • Central Asia
    • Kazakhstan
    • Kyrgyzstan
    • Tajikistan
    • Turkmenistan
    • Uzbekistan
  • Western Asia
    • Armenia
    • Azerbaijan
    • Bahrain
    • Cyprus
    • Georgia
    • Iraq
    • Israel
    • Jordan
    • Kuwait
    • Lebanon
    • Oman
    • Qatar
    • Saudi Arabia
    • State of Palestine
    • Syria
    • Turkey
    • United Arab Emirates
    • Yemen
  • More News
    • Opinion
    • Politics
    • Business
    • Entertainment
    • Fashion
    • Food
    • Health
    • Lifestyle
    • Science
    • Tech
    • Sports
  • Eastern Asia
    • China
    • Japan
    • Mongolia
    • North Korea
    • South Korea
  • South-eastern Asia
    • Brunei
    • Cambodia
    • Indonesia
    • Laos
    • Malaysia
    • Myanmar
    • Philippines
    • Singapore
    • Thailand
    • Timor Leste
    • Vietnam
  • Southern Asia
    • Afghanistan
    • Bangladesh
    • Bhutan
    • India
    • Iran
    • Maldives
    • Nepal
    • Pakistan
    • Sri Lanka
  • Central Asia
    • Kazakhstan
    • Kyrgyzstan
    • Tajikistan
    • Turkmenistan
    • Uzbekistan
  • Western Asia
    • Armenia
    • Azerbaijan
    • Bahrain
    • Cyprus
    • Georgia
    • Iraq
    • Israel
    • Jordan
    • Kuwait
    • Lebanon
    • Oman
    • Qatar
    • Saudi Arabia
    • State of Palestine
    • Syria
    • Turkey
    • United Arab Emirates
    • Yemen
  • More News
    • Opinion
    • Politics
    • Business
    • Entertainment
    • Fashion
    • Food
    • Health
    • Lifestyle
    • Science
    • Tech
    • Sports
No Result
View All Result
Morning News
No Result
View All Result
Home Western Asia United Arab Emirates

Mac malware campaign targets crypto coders — Arabian Post

by Asia Today Team
May 29, 2026
in United Arab Emirates
Reading Time: 3 mins read
21 0
A A
0
Mac malware campaign targets crypto coders — Arabian Post
25
SHARES
307
VIEWS
Share on FacebookShare on Twitter

READ ALSO

Acer lifts handheld gaming ambitions — Arabian Post

BTMOB puts Android users at takeover risk — Arabian Post


Cryptocurrency builders have change into the main focus of a brand new macOS-focused cyber marketing campaign that makes use of faux recruiter approaches, malicious assembly hyperlinks and compromised software program pipelines to steal digital belongings and unfold malware via trusted inner methods.

The exercise is being tracked as JINX-0164, a beforehand unreported financially motivated menace actor lively since at the least mid-2025. Investigators discovered that the group has focused cryptocurrency organisations by approaching builders and workers via credible LinkedIn profiles, then steering them in direction of bogus on-line assembly platforms or job-related technical duties that result in malware set up.

The marketing campaign marks a shift from standard credential theft in direction of deeper assaults on growth infrastructure. As soon as a developer’s workstation is compromised, the attacker seeks entry to inner repositories, construct methods and code distribution channels, turning the sufferer’s personal engineering atmosphere right into a path for wider an infection. At the least one intrusion unfolded over about two weeks, starting with social engineering and ending with malicious source-code modifications designed to compromise extra endpoints.

The malware on the centre of the marketing campaign is AUDIOFIX, a Python-based macOS stealer and distant entry trojan. It’s delivered via scripts hosted on spoofed infrastructure that mimics trusted expertise companies, together with faux Apple-related domains. The payload is constructed to run on each Intel and Apple Silicon machines, rising its usefulness in opposition to developer groups that rely closely on macOS laptops.

After execution, AUDIOFIX makes an attempt to assemble credentials from macOS Keychain recordsdata, browser shops, password managers, native administrator accounts, SSH keys, configuration recordsdata, shell historical past and cryptocurrency pockets information. It additionally targets periods from communications platforms akin to Slack, Discord and Telegram, giving the attacker potential entry to group discussions, engineering channels and operational particulars. Cloud secrets and techniques, together with credentials linked to AWS, Google Cloud, Azure and Cloudflare, are additionally among the many materials sought.

The attacker’s behaviour reveals a selected curiosity in software program growth pipelines reasonably than broad cloud exploitation. Though some cloud sign-in makes an attempt had been noticed, the first goal gave the impression to be the abuse of Git repositories and CI/CD methods. In a single case, the actor injected AUDIOFIX into inner repositories, altered committer names and e mail fields to impersonate different builders, pushed code on to predominant branches the place protections had been weak, and hijacked present branches when direct entry was unavailable.

This method will increase the danger of secondary infections as a result of workers who pull code or construct from compromised repositories could unknowingly execute the malware. It additionally creates a possible route into supply-chain assaults, the place malicious code will be distributed via respectable channels and seem to return from trusted inner groups.

JINX-0164 has additionally been linked to MiniRAT, a Go-based backdoor distributed earlier via a compromised model of the npm bundle @velora-dex/sdk, a toolkit related to decentralised finance exercise. That episode underlined the broader danger dealing with Web3 and crypto builders, who usually rely upon open-source packages, automated builds and fast deployment workflows.

The marketing campaign resembles techniques utilized by a number of North Korea-linked clusters which have focused cryptocurrency staff via faux jobs, coding assessments and video-call lures. Nevertheless, investigators haven’t established sufficient proof to hyperlink JINX-0164 to a state sponsor. The dearth of infrastructure overlap with publicly tracked teams has stored attribution cautious, despite the fact that the sector focus and social-engineering strategies are acquainted to menace hunters.

Using recruiter themes stays efficient as a result of builders are accustomed to technical screening, code challenges and on-line conferences. Attackers exploit that routine by presenting malicious downloads as assembly fixes, drivers or venture dependencies. The method is especially harmful in cryptocurrency corporations, the place developer machines could maintain pockets information, deployment keys, alternate credentials and entry to delicate repositories.

The findings add to rising concern over developer workstations as a part of the software program provide chain. Safety groups have historically targeted on cloud environments, manufacturing servers and perimeter controls, however the marketing campaign reveals how a single laptop computer can change into a bridge into supply code, secrets and techniques and launch methods. Sturdy department safety, verified commits, hardware-backed keys, endpoint monitoring, restricted token scopes and tighter assessment of CI/CD secrets and techniques have change into central defensive measures.

For cryptocurrency corporations, the fast danger isn’t restricted to stolen wallets. A compromised developer account can expose personal repositories, inner tooling, customer-facing code and bundle publishing rights. That mixture can enable attackers to maneuver from particular person theft to broader ecosystem compromise, particularly the place launch pipelines lack separation of duties or the place automated methods settle for code modifications with restricted scrutiny.



Source link

Tags: ArabiancampaigncoderscryptoMacmalwarePosttargets

Related Posts

Acer lifts handheld gaming ambitions — Arabian Post
United Arab Emirates

Acer lifts handheld gaming ambitions — Arabian Post

May 29, 2026
BTMOB puts Android users at takeover risk — Arabian Post
United Arab Emirates

BTMOB puts Android users at takeover risk — Arabian Post

May 28, 2026
A Strategic Focus on Quality Enhancement and Sustainable Development — Arabian Post
United Arab Emirates

A Strategic Focus on Quality Enhancement and Sustainable Development — Arabian Post

May 27, 2026
Muscat deepens maritime security ties — Arabian Post
United Arab Emirates

Muscat deepens maritime security ties — Arabian Post

May 27, 2026
Kali365 raises Microsoft 365 breach risks — Arabian Post
United Arab Emirates

Kali365 raises Microsoft 365 breach risks — Arabian Post

May 25, 2026
KPMG Launches Trusted AI Centre of Excellence to Strengthen Singapore’s Position as a Globally Trusted AI Hub — Arabian Post
United Arab Emirates

KPMG Launches Trusted AI Centre of Excellence to Strengthen Singapore’s Position as a Globally Trusted AI Hub — Arabian Post

May 26, 2026
Asia Today

Copyright © 2022 Asia Today.

Navigate Site

  • Disclaimer
  • Privacy Policy
  • Cookie Privacy Policy
  • DMCA
  • Terms and Conditions
  • Contact us

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Homepages
  • World
  • Eastern Asia
    • China
    • Japan
    • Mongolia
    • North Korea
    • South Korea
  • South-eastern Asia
    • Brunei
    • Cambodia
    • Indonesia
    • Laos
    • Malaysia
    • Myanmar
    • Philippines
    • Singapore
    • Thailand
    • Timor Leste
    • Vietnam
  • Southern Asia
    • Afghanistan
    • Sri Lanka
    • Bangladesh
    • Bhutan
    • India
    • Iran
    • Maldives
    • Nepal
    • Pakistan
    • Central Asia
    • Kazakhstan
    • Kyrgyzstan
    • Tajikistan
    • Turkmenistan
    • Uzbekistan
  • Western Asia
    • Armenia
    • Azerbaijan
    • Bahrain
    • Cyprus
    • Georgia
    • Iraq
    • Israel
    • Jordan
    • Kuwait
    • Lebanon
    • Oman
    • Qatar
    • Saudi Arabia
    • State of Palestine
    • Syria
    • Turkey
    • United Arab Emirates
    • Yemen
  • Opinion
  • Politics
  • Business
  • Entertainment
  • Fashion
  • Food
  • Health
  • Lifestyle
  • Science
  • Tech
  • Travel
  • Sports
  • About us
  • Advertise with us
  • Privacy Policy
  • Contact us
  • Support AsiaToday

Copyright © 2022 Asia Today.