JINX-0126 is an unknown threat actor targeting misconfigured PostgreSQL servers to deploy fileless XMRig-C3 cryptominers.
Analyst brief
JINX-0126 is an unknown threat actor tracked by Wiz, targeting publicly exposed PostgreSQL servers with weak or misconfigured login credentials. Their primary TTPs involve gaining access via brute-forced or guessable credentials and deploying XMRig-C3 cryptominers filelessly, using binaries with unique hashes per target to evade hash-based detection. Defenders should monitor for anomalous PostgreSQL queries, unexpected process creation, and prioritize behavioral-based detection over purely file reputation-based solutions to counter the fileless and unique-hash evasion techniques.
JINX-0126
unknown
Wiz Threat Research identified a new variant of an ongoing malicious campaign targeting misconfigured and publicly exposed PostgreSQL servers. In the observed attack, the threat actor (tracked by Wiz as JINX-0126) abuses exposed PostgreSQL instances, configured with weak and guessable login credentials, to gain access and to deploy XMRig-C3 cryptominers. This campaign was first documented by Aqua Security, but the threat actor has since evolved, implementing defense evasion techniques such as deploying binaries with a unique hash per target and executing the miner payload filelessly—likely to evade detection by CWPP solutions that rely solely on file hash reputation.