LIVE · cybersecurity feed
Live wire
vulnerability

Researchers Link 'Jewelbug' Chinese APT to Hack-for-Hire Operations

Threat intelligence researchers from Broadcom revealed that a known Chinese APT group may be linked to a lucrative crypto fraud operation

zeroday.news ·

A threat group known as Jewelbug, previously associated with Chinese state-sponsored cyber espionage, has been linked to hack-for-hire operations and financially motivated cryptocurrency fraud campaigns. Researchers from Broadcom’s Threat Hunter Team, including experts from Symantec and Carbon Black, published a report on August 13 detailing how Jewelbug uses shared infrastructure for both espionage and profit-driven activities. The group is also known by other names, including Ink Dragon, Earth Alux, REF770, and CL-STA-0049.

The Broadcom report indicates that the espionage and cryptocurrency fraud operations are not separate but are run by the same small team, utilizing shared infrastructure and a single control panel. One operator, identified as ‘ople500’ within the group’s control panel and likely managing the commercial aspects, uses the persona ‘paopaodada’ (meaning ‘bubble boss’). This individual has been advertised on Telegram for a "website ranking rental" service. Broadcom has linked this individual with high confidence to an SEO business registered in Changsha, Hunan province, and identified the sole legal representative of this company. This individual is assessed to provide access, infrastructure, and delivery for the espionage operations rather than being an active operator.

Jewelbug’s cyber espionage activities have been previously documented by other threat intelligence teams, including Trend Micro's TrendAI, Palo Alto Networks' Unit 42, and Check Point Research. The group typically gains initial access through vulnerable IIS and SharePoint servers, subsequently deploying web shells and a sophisticated backdoor known as VARGEIT, Squidoor, or FinalDraft. This malware supports various covert command-and-control (C2) methods, such as Microsoft Graph/Outlook APIs, DNS tunneling, and ICMP tunneling.

The Broadcom investigation, spanning several months, found that Jewelbug has targeted numerous government organizations across the Middle East and Southeast Asia, including over 90 police and government email addresses in South Asia. A victim database uncovered by the researchers recorded more than one million implant check-ins and over 580,000 stolen browser cookies within a three-month period. In one instance, a set of implants was configured to leverage the internal proxy of a major US aerospace and industrial manufacturer. The group also conducted a large-scale watering-hole attack, compromising more than 15 government webmail tenants in a Middle Eastern country simultaneously.

In parallel with its espionage, Jewelbug uses some of its infrastructure for cryptocurrency fraud. This financially motivated campaign targets Chinese-speaking cryptocurrency users through fake exchange-download websites. Decoy documents themed around Taiwanese government organizations suggest an interest in Taiwan as well. The common thread across the group's espionage targets appears to be government communications systems and their service providers, potentially providing long-term access to official correspondence.

Central to both the espionage and cryptocurrency fraud operations is XG-Web, a browser-based C2 platform that serves as the group's central management console. The same XG-Web infrastructure is used to manage victims from both campaigns, with implants, stolen data, and operator activity all feeding into a shared backend database.

One of the primary tools connected to this infrastructure is Antino, a Windows backdoor that communicates with operators via the Microsoft Graph API, allowing C2 traffic to blend with legitimate Microsoft cloud services. Antino has been deployed across multiple Jewelbug campaigns, often through fake software installers and themed lures. The group also utilizes a malicious Chrome and Firefox extension called ‘PDF Viewer,’ which is paired with a helper program disguised as a Microsoft Edge component. This combination provides operators with extensive browser access, enabling the theft of cookies, credentials, and browsing data, and offering a command shell on the compromised host through a native messaging component.

In addition to Antino, Jewelbug employs ClientKing, a Linux and router implant that supports multiple C2 methods, including DNS tunneling, and provides remote shell access and pivoting capabilities. The ClientKing infrastructure overlaps with the broader XG-Web ecosystem, further linking the group's diverse operations. The group also abuses Google Docs for payload delivery and C2, creating public Google documents containing obfuscated payloads that implants retrieve and execute. This method helps disguise malicious activity as legitimate traffic and reduces detection likelihood.

vulnerabilitynation-state
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Anthropic confirms Claude is down in major outage affecting multiple services

Claude is experiencing a major outage, with users reporting login problems and degraded performance across several Anthropic services. [...]

malware

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 110

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM ShieldBreak – August 2026 disclosure Kimwolf v7: An Evolution of the Kimwolf Botnet CISA, FBI and Partners Warn Organizations of […]

ddos

Large-scale DDoS attacks disrupted Threema secure messaging service

Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications. [...]

security

Mustang Panda Upgrades CoolClient With a Kernel Rootkit

Mustang Panda upgraded CoolClient with a signed kernel driver that hides processes, files and network activity, making the backdoor harder to detect. HoneyMyte, also known as Mustang Panda, has pushed its CoolClient backdoor another step deeper into Windows. Kaspersky’s latest analysis shows a new variant that can deploy a signed kernel-mode driver as a Windows […]

malware

New AmnesiaStealer macOS malware hijacks browser sessions via remote control

A new information-stealing malware called AmnesiaStealer, which targets macOS users via ClickFix attacks, includes a streaming module that allows the attacker to interactively control the victim's web browser. [...]

ai

Stopping a cyberattack while walking your dog - defensive AI security CEO says it's not ruff to do

Corma CEO tells The Reg it's building 'One ring to rule them all, for the defenders to have this power'