The operators use AI to generate thousands of fake download pages impersonating cryptocurrency exchange platforms, supported by more than 40 content-management servers and click-fraud bots that boosted their search rankings, Symantec said. The threat actor also registered hundreds of look-alike domains of major trading platforms OKX and Binance and cloaked them so that website crawlers saw the phishing content while regular visitors were redirected elsewhere.
Symantec attributes with high confidence the cryptocurrency fraud and SEO scheme to a legal representative of the company, who has used the handle "paopaodada" - Bubble Boss - on Telegram. "It is most likely that the SEO business supplied access, infrastructure and delivery to the espionage operation rather than that one person performing both roles," Symantec said.
A look inside the threat actor's exposed database revealed more than 1 million implant check-ins and more than 580,000 stolen browser cookies in less than three months of active operations, Symantec said. "One set of implants was configured to beacon out of the network of a major U.S. aerospace and industrial manufacturer."
On the espionage side, the group has developed five generations of command-and-control code and a family of implants targeting browsers, Windows endpoints, Linux servers and network devices, Symantec said. Its primary implant was a malicious Chrome and Firefox browser extension named PDF Viewer.
"Masquerading as a document reader, it requested effectively every dangerous permission the browser exposes: cookies, scripting, debugger access, web request interception, download monitoring and native messaging across all sites," Symantec said.
The malware enables near-total remote control of a victim's browser, stealing credentials and cookies, hijacking new session tokens almost in real time, executing arbitrary JavaScript, or invoking any Chrome or Firefox function on the victim's behalf, Symantec said. It could also break out of the browser through a Windows helper to run system commands.
Another tool the group uses is a Windows backdoor called Antino. It has been delivered through malicious HTML Application downloaders themed around geopolitical events, including a lure impersonating an invitation to an event run by the Washington-based Center for Strategic and International Studies. Antino has also been distributed through fake Adobe Flash and Adobe installers.
"Once running, Antino uses the Microsoft Graph API as its C&C channel, hiding its traffic inside legitimate Microsoft cloud services," Symantec said. "It is a shared tool used across the group's campaigns, recovered from infected hosts in the Middle East and submitted to public scanners from victims in the Middle East and South Asia, and it is the on-host backdoor that the fake-update lure [imitating CSIS] ultimately installs on the endpoint."
"Jewelbug's victim database holds more than 1 million implant check-in rows, more than 580,000 stolen browser cookies, several thousand captured credentials and more than 2,300 exfiltrated email bodies," Symantec said.