Cryptojacking Campaign Targets DevOps Tools, Experts Warn

Key Points:
  • JINX-0132 targets DevOps tools for large-scale cryptojacking attacks.
  • 25% of cloud environments vulnerable to attacks.
  • Wiz experts stress configuring DevOps tools to block attacks.

JINX-0132 hacker group exploits DevOps tool vulnerabilities for cryptojacking, impacting cloud environments.

Wiz security has uncovered the JINX-0132 hacking group exploiting DevOps tools for cryptojacking, threatening about 25% of cloud environments. The campaign underscores cloud configuration management’s necessity, with experts urging timely software updates to prevent attacks.

JINX-0132 Exploits: A 25% Cloud Vulnerability Concern

Wiz security has identified the JINX-0132 cyber group exploiting vulnerabilities across HashiCorp Nomad/Consul, Docker API, and Gitea for cryptojacking. Using default configurations, JINX-0132 operators deploy XMRig mining software, exploiting over 30% of misconfigured setups in exposed networks.

Immediate changes include targeted attacks on unprotected cloud systems, leveraging DevOps tool vulnerabilities. Wiz researchers stress that updating configurations to include security measures can significantly mitigate risks and defend against these operations, affecting 5% of exposed DevOps tools directly.

Gili Tikochinski, Threat Researcher, Wiz, “The JINX-0132 campaign represents a new approach to exploiting misconfigurations in DevOps tools, targeting public-facing instances for cryptojacking activities.”

Monero Price Movement amid Cryptojacking Findings

Did you know? The first known case of unauthenticated Nomad deployments being used for crypto mining was documented in 2025, indicating an ongoing risk to poorly configured cloud systems.

Monero (XMR), targeted in this campaign, experienced a price of $330.96 with a market cap of $6.11 billion. While the trading volume saw a 19.54% decrease, prices dropped 5.36% in 24 hours despite a 53.70% jump over 60 days, as per CoinMarketCap data.

monero-daily-chart-3
Monero(XMR), daily chart, screenshot on CoinMarketCap at 15:52 UTC on June 4, 2025. Source: CoinMarketCap

Research from Coincu concludes that stronger cloud security measures could reduce cryptojacking risks. Enhancing API security, per analysts, might offer technological shields, while heightened awareness invites industry-wide regulatory review to prevent economic exploitation.

Rate this post

Other Posts: