“The two are not separate ventures that happen to share a name: our investigation revealed they are run by the same small team, on shared infrastructure, from one control panel,” Broadcom’s Threat Hunter Team wrote on August 13, describing an actor they label Jewelbug.
Scale of compromise: more than one million implant check‑ins and 580,000 stolen cookies
Broadcom’s report documents striking volume. In less than three months of activity the researchers found a victim database recording more than one million implant check‑ins and over 580,000 stolen browser cookies. The signals, the team said, came from campaigns that touched government communications systems and service providers across the Middle East, Southeast Asia and South Asia — including more than 90 police and government email addresses in South Asia alone.
Shared command-and-control: XG‑Web, Antino and ClientKing
At the center of the operation is XG‑Web, a browser‑based command‑and‑control (C2) platform that Broadcom described as the group’s central management console. XG‑Web fed a shared backend database where implants, stolen data and operator activity converged, according to the report. One of the primary Windows backdoors tied into that ecosystem is Antino, which communicates via the Microsoft Graph API so C2 traffic can blend with legitimate Microsoft cloud service calls.
Broadcom also detailed a Linux and router implant known as ClientKing. ClientKing supported multiple C2 methods including DNS tunnelling, provided remote shell access and pivoting capabilities, and showed infrastructure overlap with XG‑Web. The combination of Antino and ClientKing — plus use of browser extensions and helper binaries — created cross‑platform reach across targets.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleEspionage techniques and targets: web shells, watering‑holes and API abuse
Researchers said Jewelbug typically gained initial access through vulnerable IIS and SharePoint servers, then deployed web shells and a backdoor tracked in the industry as VARGEIT, Squidoor or FinalDraft. The malware family supported covert C2 over Microsoft Graph/Outlook APIs, DNS tunnelling and ICMP tunnelling.
In one large operation a single planted script placed a watering‑hole on more than 15 government webmail tenants in a Middle Eastern country simultaneously. One set of implants was configured to use the internal proxy of a major US aerospace and industrial manufacturer, the report noted. Broadcom emphasized that the common thread across espionage targets was government communications systems and the service providers that host them — assets that can provide long‑term access to official correspondence.
Crypto fraud campaign: fake exchange downloads and browser‑stealing extensions
Broadcom linked portions of the same infrastructure to a financially motivated campaign targeting Chinese‑speaking cryptocurrency users. The fraud used fake exchange‑download portals and malicious browser tooling. One malicious extension, named ‘PDF Viewer,’ paired with a helper program disguised as a Microsoft Edge component and a native messaging component. Together, they enabled comprehensive browser access — stealing cookies, credentials and browsing data while also providing a command shell on the host.
The researchers added that decoy documents themed around Taiwanese government organizations appeared in the fraud campaigns, indicating an interest beyond the Chinese‑language crypto lures.
Operator identities, commercial ties and Telegram advertising
Broadcom’s Threat Hunter Team linked operations in the combined espionage‑and‑fraud ecosystem to a small operator team managed through a single control panel. At least one operator, identified as ‘ople500’ in the control panel and using the persona ‘paopaodada’ (translated as “bubble boss”), was advertised on Telegram as the contact for a “website ranking rental” service. Broadcom associated that persona “with high confidence” to a company registered in Changsha, Hunan.
The team identified the company’s sole legal representative and assessed that this person supplies access, infrastructure and delivery to the espionage operation rather than being one of the hands‑on operators.
How technologists, policymakers and affected enterprises should react
- Technologists and security teams: monitor for known indicators such as Antino behavior over Microsoft Graph APIs, XG‑Web‑style backend activity, and abuse of Google Docs for payload delivery; pay special attention to IIS and SharePoint exposure and to browser extensions and helper binaries that can exfiltrate cookies.
- Policymakers and regulators overseeing communications providers: note the report’s finding that service providers and government mail systems are common targets; examine risk to long‑term access and potential policy levers for hardening hosted mail and webmail tenants.
- Affected enterprises and critical manufacturers: the report’s detail that an implant was configured to use an internal proxy of a major aerospace and industrial manufacturer underscores the need to inspect proxy and internal trust‑boundaries for signs of lateral activity linked to external campaigns.
Broadcom’s analysis ties an actor variously tracked as Jewelbug, Ink Dragon, Earth Alux, REF770 and CL‑STA‑0049 to an unusual business model: a small team that blends espionage against governments and service providers with commercial crypto fraud, all administered from a common control plane. The shared infrastructure — XG‑Web, Antino, ClientKing and malicious browser tooling — is the throughline that links the two profitable lines of activity. As the researchers noted, the question is not whether the ventures share a name but how the shared backend continues to enable both intelligence collection and criminal monetization.




