<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/jinx-0132-cryptojacking-campaign-targets-misconfigured-devops-servers-rndjide2y" -->

---
title: JINX-0132 Cryptojacking Campaign Targets Misconfigured...
description: A new cryptojacking campaign called JINX-0132 exploits misconfigured DevOps tools like Docker, Gitea, HashiCorp Consul, and Nomad to mine cryptocurrencies....
canonical: https://daily.dev/posts/jinx-0132-cryptojacking-campaign-targets-misconfigured-devops-servers-rndjide2y
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: JINX-0132 Cryptojacking Campaign Targets Misconfigured DevOps Servers | daily.dev
og:description: A new cryptojacking campaign called JINX-0132 exploits misconfigured DevOps tools like Docker, Gitea, HashiCorp Consul, and Nomad to mine cryptocurrencies....
og:url: https://daily.dev/posts/jinx-0132-cryptojacking-campaign-targets-misconfigured-devops-servers-rndjide2y
og:image: https://api.daily.dev/og/posts/RnDjide2Y.png
og:image:alt: JINX-0132 Cryptojacking Campaign Targets Misconfigured DevOps Servers
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# JINX-0132 Cryptojacking Campaign Targets Misconfigured DevOps Servers

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 2 upvotes · 0 comments

## Summary

A new cryptojacking campaign called JINX-0132 exploits misconfigured DevOps tools like Docker, Gitea, HashiCorp Consul, and Nomad to mine cryptocurrencies. This marks the first documented case of exploiting Nomad misconfigurations in the wild. The attackers target cloud infrastructure with insecure default settings, affecting 25% of cloud environments with 5% exposed to the internet. Organizations can defend by enforcing access controls, enabling security features, keeping tools updated, and following DevOps security best practices.

## Content

A new cryptojacking campaign, named JINX-0132, has emerged, targeting misconfigured DevOps servers to mine cryptocurrencies, especially leveraging tools such as Docker, Gitea, HashiCorp Consul, and Nomad. Exploiting known vulnerabilities and misconfigurations, the attackers employ open-source tools retrieved from GitHub, adeptly evading attribution by utilizing legitimate platforms.

In a concerning revelation, this campaign marks the first documented case of exploiting Nomad misconfigurations in the wild. Instances compromised by JINX-0132 have been found managing resources worth tens of thousands of dollars each month, significantly impacting enterprise computing costs worldwide.

The JINX-0132 group primarily targets cloud infrastructure employing insecure default settings or being publicly exposed. Research indicates that as many as 25% of cloud environments run these vulnerable tools, with 5% exposing them directly to the internet, of which 30% are misconfigured. The attackers capitalize on these weaknesses, using default insecure configurations, disabled security features, and publicly accessible APIs to gain remote code execution capabilities and install XMRig mining software.

Organizations can defend against these cryptojacking tactics by enforcing robust access controls, enabling security features, keeping tools updated, and adhering strictly to security best practices for DevOps infrastructure. By securing APIs, demanding authentication, and examining configurations, enterprises can fortify their defenses against such exploitative attacks. This proactive stance will mitigate the high costs associated with cryptojacking and protect computing resources from unauthorized mining operations.

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments
- [CNCF Unveils Schedule for KubeCon \+ CloudNativeCon Europe 2026](https://daily.dev/posts/cncf-unveils-schedule-for-kubecon-cloudnativecon-europe-2026-ikhcoa5cb) · CNCF · 2 upvotes · 0 comments
- [CNCF Debuts KubeCon \+ CloudNativeCon Japan 2026 Schedule](https://daily.dev/posts/cncf-debuts-kubecon-cloudnativecon-japan-2026-schedule-xp5pyudub) · CNCF · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cyber](https://daily.dev/tags/cyber), [#devops](https://daily.dev/tags/devops), [#docker](https://daily.dev/tags/docker), [#hashicorp](https://daily.dev/tags/hashicorp)

[View this post on daily.dev](https://daily.dev/posts/jinx-0132-cryptojacking-campaign-targets-misconfigured-devops-servers-rndjide2y)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"JINX-0132 Cryptojacking Campaign Targets Misconfigured DevOps Servers","url":"https://daily.dev/posts/jinx-0132-cryptojacking-campaign-targets-misconfigured-devops-servers-rndjide2y","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/jinx-0132-cryptojacking-campaign-targets-misconfigured-devops-servers-rndjide2y"},"datePublished":"2025-06-03T10:01:54.155Z","dateModified":"2025-06-03T11:29:28.724Z","description":"A new cryptojacking campaign called JINX-0132 exploits misconfigured DevOps tools like Docker, Gitea, HashiCorp Consul, and Nomad to mine cryptocurrencies....","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/435fa0600a6573414da8529f2fd7b4ad?_a=AQAEulh","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/435fa0600a6573414da8529f2fd7b4ad?_a=AQAEulh","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/jinx-0132-cryptojacking-campaign-targets-misconfigured-devops-servers-rndjide2y","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":2},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,cyber,devops,docker,hashicorp","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"JINX-0132 Cryptojacking Campaign Targets Misconfigured DevOps Servers"}]}
```

