
The Jewelbug hacker group has been finishing up espionage operations concentrating on governments and militaries while additionally partaking in cryptocurrency fraud.
Though the menace actor has focused authorities companies and organizations in crucial sectors, together with protection, telecommunications, training, and aviation, its cryptocurrency-related exercise means that they could additionally function as a hack-for-hire group that seeks to revenue from cybercrime.
In a current operation, Jewelbug (often known as Earth Alux and REF7707) compromised webmail accounts belonging to fifteen authorities tenants as a part of a marketing campaign concentrating on a rustic within the Center East.
Researchers at Symantec discovered that the espionage marketing campaign and the cryptocurrency fraud have been carried out from the identical management panel.
The China-based hacker group gained write entry to the shared webmail set up and inserted a malicious script into its frequent template. The script then ran on login pages and mailbox views throughout 15 tenants.
.jpg)
Supply: Symantec
After execution, the script established a WebSocket connection to the attacker’s command-and-control (C2) server, exfiltrated webmail cookies, and retrieved the person’s electronic mail deal with to find out whether or not it belonged to a focused authorities area.
Worthwhile targets would obtain a pretend Adobe Flash replace immediate, which installs the primary payload on Home windows, the Antino backdoor, and browser tooling.
Other than Antino, the menace actor additionally makes use of the XG-Internet remote-access and data-theft framework for managing campaigns and sufferer data.

Supply: Symantec
Based on Symantec, Jewelbug delivers Antino by means of malicious HTA recordsdata and pretend Adobe Flash/Adobe installers, after which makes use of it to deploy further payloads.
One of many payloads is a malicious browser extension for Chrome and Firefox, named PDF Viewer, which steals cookies and credentials, intercepts site visitors, injects JavaScript, and remotely exposes browser capabilities.

Supply: Symantec
Symantec traced Antino infections to Jewelbug’s infrastructure after which obtained visibility into the group’s C2 administration platform, database, server logs, supply code, and operator recordsdata.
The information confirmed that the hackers ran a large-scale espionage operation and “an industrial-scale cryptocurrency fraud enterprise.”
“Jewelbug’s sufferer database holds a couple of million implant check-in rows, greater than 580,000 stolen browser cookies, a number of thousand captured credentials, and greater than 2,300 exfiltrated electronic mail our bodies,” Symantec researchers be aware.
Relating to the espionage half, Jewelbug focused authorities and army organizations throughout the Center East, Southeast Asia, and South Asia.
“Runtime server logs recorded roughly 1.1 million geolocation occasions towards roughly 4,300 distinct supply IP addresses: roughly 87,200 connections from a Southeast Asian nation (concentrating on state telecom and army networks), roughly 53,100 from a Center Jap nation (throughout the nationwide provider’s ranges, together with Starlink-connected addresses within the capital), and roughly 15,000 from a second Southeast Asian nation (together with authorities ministry infrastructure),” Symantec says.
The researchers defined that the menace actor obtained write entry to the webmail set up utilized by a number of authorities ministries and companies after compromising a shared web-hosting platform operated by the state telecommunications supplier and nationwide providers company.
By injecting a single script tag, the menace actor ensured that the JavaScript payload opened a WebSocket to the C2 each time a person on one in all 9 authorities domains logged in.
“A single marketing campaign spanned greater than 15 authorities webmail tenants, with the hook firing on the login web page and each mailbox view,” Symantec says.
The cryptocurrency theft operations are backed by AI-generated articles driving site visitors to pretend crypto alternate websites and click-fraud bots that manipulate search rankings.

Supply: Symantec
Based on the researchers, the menace actor depends on an automatic assault pipeline that scrapes key phrases, generates hundreds of faux obtain pages utilizing AI, and publishes them “throughout a 44-server content-management fleet and tons of of lookalike domains” impersonating OKX and Binance. Utilizing click on bots, Jewelbug manipulates rankings to advertise their fraudulent pages.
The fraud makes use of different lures, as effectively: sports activities betting, pirated livestream portals, and personal detective scams.
Symantec researchers have excessive confidence attributing Jewelbug’s financially-motivated actions to a Chinese language firm that advertises search engine marketing providers.
Jewelbug additionally makes use of a Rust-based implant referred to as ‘ClientKing’ that targets Linux servers, ARM64 units, and ASUS routers, and helps command execution, SOCKS proxying, DNS tunneling, and in-memory kernel module loading.
The hackers used public Google Docs to host obfuscated payloads retrieved and executed by their implants, serving to the malicious site visitors mix in with professional Google providers.
Symantec revealed indicators of compromise associated to noticed Jewelbug exercise, in addition to a extra detailed technical report describing the menace actor’s tooling and tradecraft, their monetary operation, and the infrastructure utilized in assaults.
Total prevention scores can conceal what occurs after preliminary entry. As soon as attackers are utilizing legitimate credentials, prevention drops sharply.
The Blue Report 2026 measures defenses approach by approach throughout 338 million simulations run in buyer manufacturing environments.













