A threat group known as Jewelbug, previously associated with Chinese state-sponsored cyber espionage, has been linked to hack-for-hire operations and financially motivated cryptocurrency fraud campaigns. Researchers from Broadcom’s Threat Hunter Team, including experts from Symantec and Carbon Black, published a report on August 13 detailing how Jewelbug uses shared infrastructure for both espionage and profit-driven activities. The group is also known by other names, including Ink Dragon, Earth Alux, REF770, and CL-STA-0049.
The Broadcom report indicates that the espionage and cryptocurrency fraud operations are not separate but are run by the same small team, utilizing shared infrastructure and a single control panel. One operator, identified as ‘ople500’ within the group’s control panel and likely managing the commercial aspects, uses the persona ‘paopaodada’ (meaning ‘bubble boss’). This individual has been advertised on Telegram for a "website ranking rental" service. Broadcom has linked this individual with high confidence to an SEO business registered in Changsha, Hunan province, and identified the sole legal representative of this company. This individual is assessed to provide access, infrastructure, and delivery for the espionage operations rather than being an active operator.
Jewelbug’s cyber espionage activities have been previously documented by other threat intelligence teams, including Trend Micro's TrendAI, Palo Alto Networks' Unit 42, and Check Point Research. The group typically gains initial access through vulnerable IIS and SharePoint servers, subsequently deploying web shells and a sophisticated backdoor known as VARGEIT, Squidoor, or FinalDraft. This malware supports various covert command-and-control (C2) methods, such as Microsoft Graph/Outlook APIs, DNS tunneling, and ICMP tunneling.
The Broadcom investigation, spanning several months, found that Jewelbug has targeted numerous government organizations across the Middle East and Southeast Asia, including over 90 police and government email addresses in South Asia. A victim database uncovered by the researchers recorded more than one million implant check-ins and over 580,000 stolen browser cookies within a three-month period. In one instance, a set of implants was configured to leverage the internal proxy of a major US aerospace and industrial manufacturer. The group also conducted a large-scale watering-hole attack, compromising more than 15 government webmail tenants in a Middle Eastern country simultaneously.
In parallel with its espionage, Jewelbug uses some of its infrastructure for cryptocurrency fraud. This financially motivated campaign targets Chinese-speaking cryptocurrency users through fake exchange-download websites. Decoy documents themed around Taiwanese government organizations suggest an interest in Taiwan as well. The common thread across the group's espionage targets appears to be government communications systems and their service providers, potentially providing long-term access to official correspondence.
Central to both the espionage and cryptocurrency fraud operations is XG-Web, a browser-based C2 platform that serves as the group's central management console. The same XG-Web infrastructure is used to manage victims from both campaigns, with implants, stolen data, and operator activity all feeding into a shared backend database.
One of the primary tools connected to this infrastructure is Antino, a Windows backdoor that communicates with operators via the Microsoft Graph API, allowing C2 traffic to blend with legitimate Microsoft cloud services. Antino has been deployed across multiple Jewelbug campaigns, often through fake software installers and themed lures. The group also utilizes a malicious Chrome and Firefox extension called ‘PDF Viewer,’ which is paired with a helper program disguised as a Microsoft Edge component. This combination provides operators with extensive browser access, enabling the theft of cookies, credentials, and browsing data, and offering a command shell on the compromised host through a native messaging component.
In addition to Antino, Jewelbug employs ClientKing, a Linux and router implant that supports multiple C2 methods, including DNS tunneling, and provides remote shell access and pivoting capabilities. The ClientKing infrastructure overlaps with the broader XG-Web ecosystem, further linking the group's diverse operations. The group also abuses Google Docs for payload delivery and C2, creating public Google documents containing obfuscated payloads that implants retrieve and execute. This method helps disguise malicious activity as legitimate traffic and reduces detection likelihood.






