Skip to main content
Threat IntelligenceEmerging Threats

Jewelbug Hacker Group Exposes Dual Threat of Espionage and Crypto Fraud

Government building exterior with subtle hint of computer infrastructure.
“Jewelbug’s victim database holds more than one million implant check-in rows, more than 580,000 stolen browser cookies, several thousand captured credentials, and more than 2,300 exfiltrated email bodies,” Symantec researchers note.

How the group breached shared government webmail

Symantec reports that the China-based hacker group known as Jewelbug — also tracked as Earth Alux and REF7707 — obtained write access to a shared web-hosting platform used by a state telecommunications provider and a national services agency. By inserting a single malicious script into a common webmail template, the actors ensured the payload ran on login pages and mailbox views across at least 15 government webmail tenants.

The injected JavaScript opened a WebSocket connection to the attackers’ command-and-control (C2) server on each login. That connection exfiltrated webmail cookies and retrieved the user’s email address to check whether the account belonged to a targeted government domain. When a login belonged to a high-value target, the page presented a fake Adobe Flash update prompt which, if executed, installed the Antino backdoor and browser tooling on Windows machines.

Espionage reach and regional footprint

Symantec says Jewelbug conducted espionage operations against governments and militaries across the Middle East, Southeast Asia, and South Asia. Runtime server logs recorded roughly 1.1 million geolocation events from approximately 4,300 distinct source IP addresses. The logs show roughly 87,200 connections from a Southeast Asian country (targeting state telecom and military networks), roughly 53,100 from a Middle Eastern country (including national carrier ranges and Starlink-connected addresses in the capital), and about 15,000 from a second Southeast Asian country (including government ministry infrastructure).

The company’s analysis describes a single campaign that spanned more than 15 government webmail tenants, with the malicious hook firing on the login page and every mailbox view for users of nine government domains.

Parallel — and large-scale — cryptocurrency fraud

Alongside espionage, Symantec documents an “industrial-scale cryptocurrency fraud business” run from the same C2 management platform. The fraud operation uses AI-generated articles to drive traffic to fake crypto exchange sites and employs click-fraud bots to manipulate search rankings. The actors automated a pipeline that scrapes keywords, generates thousands of AI-created download pages, and publishes them across a 44-server content-management fleet and hundreds of lookalike domains impersonating OKX and Binance.

Other lures include sports betting, pirated livestream portals, and private detective scams. Symantec reports high confidence linking the financially motivated side of the operation to a China-based company that advertises search-engine-optimization services.

Tooling, persistence, and operational tradecraft

Symantec’s visibility into Jewelbug’s infrastructure came after tracing Antino infections back to the group’s systems and obtaining the C2 management platform, database, server logs, source code, and operator files. Jewelbug delivers Antino via malicious HTA files and fake Adobe installers and uses it to deploy additional payloads, including a malicious browser extension named PDF Viewer for Chrome and Firefox. That extension steals cookies and credentials, intercepts traffic, injects JavaScript, and remotely exposes browser functions.

Beyond Antino, the group uses the XG-Web remote-access and data-theft framework to manage campaigns and victim information. The actors also deploy a Rust-based implant called ClientKing that targets Linux servers, ARM64 devices, and ASUS routers, supports command execution, SOCKS proxying, DNS tunneling, and in-memory kernel module loading. To blend malicious activity with legitimate traffic, they hosted obfuscated payloads on public Google Docs and retrieved them from the implants.

What this means for technologists, policymakers, and affected government ministries

  • Technologists and security teams: The single-template compromise shows how write access to shared web infrastructure allows broad, low-effort surveillance; teams should prioritize detection of script injections and anomalous WebSocket connections tied to webmail templates, and monitor for large volumes of stolen cookies and credential captures as indicators of active campaigns.
  • Policymakers and regulators: Symantec’s linkage of financial fraud to a firm advertising SEO services highlights a cross-border criminal-commercial nexus; regulators and law enforcement may need to consider oversight of lookalike domain networks and the platforms that host automated content fleets driving fraudulent campaigns.
  • Government ministries and national carriers: The campaign demonstrates risk to any tenant that shares web-hosting infrastructure with other agencies; ministries should evaluate segregation of hosting environments and the integrity of shared templates, and review logs for unexpected external WebSocket endpoints and mass-exfiltration events.

Symantec published indicators of compromise and a detailed technical report describing Jewelbug’s tooling, tradecraft, financial operation, and infrastructure. The company’s findings paint a single picture: an espionage campaign and an organized criminal enterprise running from the same operational platform, with hundreds of thousands of stolen artifacts and a database of more than one million implant check-ins.

https://www.bleepingcomputer.com/news/security/hackers-breach-govt-webmail-while-running-parallel-crypto-fraud/