Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

darkreading+1security+1darkreadingA China-based hackers-for-hire group dubbed "Jewelbug" has been conducting government espionage and cryptocurrency fraud simultaneously from the same command-and-control infrastructure, according to research published Thursday by the Symantec Threat Hunter Team. The finding reveals a rare dual-purpose threat actor operating at scale across multiple continents.
Jewelbug — also tracked as Earth Alux, REF7707, and CL-STA-0049 — manages both its espionage campaigns and its crypto fraud business through a centralized platform called XG-Web, built as a React application over a Node.js backend. The group's victim database recorded more than one million implant check-ins, over 580,000 stolen browser cookie jars, and more than 2,300 exfiltrated email bodies.security+1
"This is quite different to cases where we've seen state-sponsored actors dabbling in cybercrime to make a little extra money," said Dick O'Brien, principal intelligence analyst for Symantec's Threat Hunter Team. "The sheer scale of the fraud business is the biggest clue. They aren't just making a little extra money by moonlighting."darkreading
On the espionage side, the group's most ambitious operation involved compromising a shared web-hosting platform run by a Middle Eastern state telecommunications provider, planting a single malicious script that placed a watering hole across more than 15 government webmail tenants at once. Other campaigns targeted navy, police, and army intelligence bodies in Southeast Asia and a major U.S. aerospace and industrial manufacturer.security+1
The financial arm of the operation uses artificial intelligence to generate thousands of fake cryptocurrency exchange pages impersonating platforms like OKX and Binance, managed by more than 40 content-management servers. The group's malicious browser extension, disguised as "PDF Viewer," can silently replace a victim's cryptocurrency wallet address with one controlled by the attackers during transactions. The crypto fraud primarily targets Chinese-speaking victims and is tied to a registered company in Hunan Province, China.cryptobriefing+1
Symantec assesses with high confidence that the cryptocurrency fraud operation is run by a named individual identified through government-issued identity documents and a business license. While there is no direct evidence linking Jewelbug to the Chinese state, O'Brien noted that the group's targeting makes other explanations unlikely. "Use of third-party contractors has grown a lot among nation-states," he said. "That's mainly down to the scale China wants to operate at in cyberspace."darkreading+1
The group's operational security was described as uneven — operators repeatedly tested their own stealer against their own browsers and reused credentials across infrastructure — leaving what O'Brien called "a trail of evidence behind them."security+1