LIVE · cybersecurity feed
Live wire
breach

Hackers breach govt webmail while running parallel crypto fraud

The Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud. [...]

zeroday.news ·

A hacking group known as Jewelbug, also tracked as Earth Alux and REF7707, has been observed conducting parallel operations involving both state-sponsored espionage and large-scale cryptocurrency fraud. Researchers at Symantec identified the group's activities, which include targeting government and military entities in the Middle East, Southeast Asia, and South Asia, while simultaneously running an "industrial-scale" cryptocurrency scam.

In a recent espionage campaign, Jewelbug compromised webmail accounts across 15 government tenants in a Middle Eastern country. The attackers gained write access to a shared webmail installation, which was hosted on a platform operated by the state telecommunications provider and national services agency. They then injected a malicious script into the common webmail template. This script executed on login pages and mailbox views for users across nine government domains.

Upon execution, the script established a WebSocket connection to the attackers' command-and-control (C2) server. It then exfiltrated webmail cookies and retrieved the user's email address to determine if it belonged to a targeted government domain. For high-value targets, a fake Adobe Flash update prompt would appear, which, if clicked, installed the Antino backdoor and additional browser tooling on Windows systems.

Beyond Antino, Jewelbug also employs the XG-Web remote-access and data-theft framework for managing campaigns and victim information. Antino is typically delivered via malicious HTA files or fake Adobe Flash/Adobe installers. One of the payloads deployed by Antino is a malicious browser extension named "PDF Viewer," compatible with Chrome and Firefox. This extension is designed to steal cookies and credentials, intercept traffic, inject JavaScript, and remotely expose browser functions. The group also uses a Rust-based implant called ClientKing, which targets Linux servers, ARM64 devices, and ASUS routers, offering capabilities like command execution, SOCKS proxying, DNS tunneling, and in-memory kernel module loading. Jewelbug has been observed using public Google Docs to host obfuscated payloads, allowing malicious traffic to blend with legitimate Google services.

Symantec researchers gained insight into Jewelbug's C2 management platform, database, server logs, source code, and operator files after tracing Antino infections to the group's infrastructure. This data revealed the extent of their operations, including a victim database containing over one million implant check-in rows, more than 580,000 stolen browser cookies, thousands of captured credentials, and over 2,300 exfiltrated email bodies.

Geolocation events recorded in runtime server logs showed approximately 1.1 million connections from around 4,300 distinct source IP addresses. This included about 87,200 connections from a Southeast Asian country, targeting state telecom and military networks; roughly 53,100 from a Middle Eastern country, across the national carrier's ranges and Starlink-connected addresses; and approximately 15,000 from a second Southeast Asian country, including government ministry infrastructure.

The cryptocurrency fraud operation runs in parallel to the espionage activities, utilizing AI-generated articles to drive traffic to fake crypto exchange websites and employing click-fraud bots to manipulate search rankings. The threat actor uses an automated attack pipeline that scrapes keywords, generates thousands of fake download pages with AI, and publishes them across a 44-server content-management fleet and hundreds of lookalike domains impersonating platforms like OKX and Binance. These fraudulent pages are then promoted through click bots. Other lures for the financial fraud include sports betting, pirated livestream portals, and private detective scams. Symantec has high confidence in attributing Jewelbug's financially motivated activities to a Chinese company that advertises SEO services.

breachvulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Sophisticated Cyberattack Exposes Data of 678,000 French Taxpayers

France’s tax agency says hackers stole data on 678,000 taxpayers, including income and tax details, in a sophisticated cyberattack. A threat actor claimed to have breached France’s tax agency in late June. France’s tax administration confirmed that a cyberattack exposed personal data of 678,000 individuals and businesses, prompting an immediate criminal investigation. The cybercrime unit […]

security

Anthropic confirms Claude is down in major outage affecting multiple services

Claude is experiencing a major outage, with users reporting login problems and degraded performance across several Anthropic services. [...]

malware

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 110

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM ShieldBreak – August 2026 disclosure Kimwolf v7: An Evolution of the Kimwolf Botnet CISA, FBI and Partners Warn Organizations of […]

ddos

Large-scale DDoS attacks disrupted Threema secure messaging service

Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications. [...]

security

Mustang Panda Upgrades CoolClient With a Kernel Rootkit

Mustang Panda upgraded CoolClient with a signed kernel driver that hides processes, files and network activity, making the backdoor harder to detect. HoneyMyte, also known as Mustang Panda, has pushed its CoolClient backdoor another step deeper into Windows. Kaspersky’s latest analysis shows a new variant that can deploy a signed kernel-mode driver as a Windows […]

malware

New AmnesiaStealer macOS malware hijacks browser sessions via remote control

A new information-stealing malware called AmnesiaStealer, which targets macOS users via ClickFix attacks, includes a streaming module that allows the attacker to interactively control the victim's web browser. [...]