This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.
Consent Selection
Details
  • Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
  • Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
    • We do not use cookies of this type.

  • Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
    • We do not use cookies of this type.

  • Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
    • We do not use cookies of this type.

  • Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    • __emg_sidPending
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      __emg_vidPending
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      nl-read-countPending
      Maximum Storage Duration: PersistentType: HTML Local Storage
Cookie declaration last updated on 8/12/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.
NewsLayer

Install NewsLayer

Get the app experience — one tap from your home screen, instant loads and breaking-news alerts.

NewsLayer.com
NewsLayer PulseLIVEBTC$63,006-0.01%ETH$1,892+0.72%SOL$75.11-0.32%XRP$0.9973-0.30%DOGE$0.07+0.55%ADA$0.1763+0.04%Total Cap$2.27T-0.02%Layer Index43 Neutral
BreakingExternal ReportingPublicado hace 4 días

Chinese Hackers Run Dual Operations: Espionage and Crypto Fraud

A well-rounded Chinese hacking group targets foreign governments and Chinese-speaking victims alike, researchers found - espionage by day, cryptocurrency fraud business on the side.

Chinese Hackers Run Dual Operations: Espionage and Crypto Fraud
Publisher GovInfoSecurity 3 min de lectura
Image via GovInfoSecurity
Traduciendo…

Layer Index

43

↑ 1 pts in 24h

Chinese Hackers Run Dual Operations: Espionage and Crypto Fraud

Symantec Says Chinese Cyber Operations Increasingly Depend on Contractors Tiffany WangAugust 13, 2026    

A well-rounded Chinese hacking group targets foreign governments and Chinese-speaking victims alike, researchers found - espionage by day, cryptocurrency fraud business on the side.

The threat actor, tracked as Jewelbug or Earth Alux, operates attacks against governments and militaries in Asia and the Middle East, as well as commits for-profit crypto theft from the same control panel with a single victim database, threat intelligence firm Symantec said.

Hackers for hire are quite common in the Chinese cyber ecosystem, Dick O'Brien, principal intelligence analyst on this research, told ISMG. "While many nation states prefer to keep everything in-house, China appears to be operating at such a scale in cyberspace that they need to meet that capacity with contractors," he said (see: Chinese Data Leak Reveals Salt Typhoon Contractors).

The group's commercial arm is tied to a registered company in the inland Chinese province of Hunan. It is registered as a "search-ranking rental" provider and advertised as such on Telegram. It actually is a search-engine-optimization poisoning pipeline that generates phishing pages with artificial intelligence tools, Symantec said.

The operators use AI to generate thousands of fake download pages impersonating cryptocurrency exchange platforms, supported by more than 40 content-management servers and click-fraud bots that boosted their search rankings, Symantec said. The threat actor also registered hundreds of look-alike domains of major trading platforms OKX and Binance and cloaked them so that website crawlers saw the phishing content while regular visitors were redirected elsewhere.

Symantec attributes with high confidence the cryptocurrency fraud and SEO scheme to a legal representative of the company, who has used the handle "paopaodada" - Bubble Boss - on Telegram. "It is most likely that the SEO business supplied access, infrastructure and delivery to the espionage operation rather than that one person performing both roles," Symantec said.

A look inside the threat actor's exposed database revealed more than 1 million implant check-ins and more than 580,000 stolen browser cookies in less than three months of active operations, Symantec said. "One set of implants was configured to beacon out of the network of a major U.S. aerospace and industrial manufacturer."

On the espionage side, the group has developed five generations of command-and-control code and a family of implants targeting browsers, Windows endpoints, Linux servers and network devices, Symantec said. Its primary implant was a malicious Chrome and Firefox browser extension named PDF Viewer.

"Masquerading as a document reader, it requested effectively every dangerous permission the browser exposes: cookies, scripting, debugger access, web request interception, download monitoring and native messaging across all sites," Symantec said.

The malware enables near-total remote control of a victim's browser, stealing credentials and cookies, hijacking new session tokens almost in real time, executing arbitrary JavaScript, or invoking any Chrome or Firefox function on the victim's behalf, Symantec said. It could also break out of the browser through a Windows helper to run system commands.

Another tool the group uses is a Windows backdoor called Antino. It has been delivered through malicious HTML Application downloaders themed around geopolitical events, including a lure impersonating an invitation to an event run by the Washington-based Center for Strategic and International Studies. Antino has also been distributed through fake Adobe Flash and Adobe installers.

"Once running, Antino uses the Microsoft Graph API as its C&C channel, hiding its traffic inside legitimate Microsoft cloud services," Symantec said. "It is a shared tool used across the group's campaigns, recovered from infected hosts in the Middle East and submitted to public scanners from victims in the Middle East and South Asia, and it is the on-host backdoor that the fake-update lure [imitating CSIS] ultimately installs on the endpoint."

"Jewelbug's victim database holds more than 1 million implant check-in rows, more than 580,000 stolen browser cookies, several thousand captured credentials and more than 2,300 exfiltrated email bodies," Symantec said.

Última Hora

No te pierdas ninguna noticia de última hora

Advertisement

House — Advertise on NewsLayer
NewsLayerAd

Sourced by

Originally reported by GovInfoSecurity

NewsLayer coverage based on externally reported material.

The Daily Brief

The onchain economy, before your day starts.

Curated markets, onchain insights, and key headlines — delivered every weekday morning.

Weekdays · Free · ~5 minute read

Noticias Relacionadas