NewsLayer.com

Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side

A months-long investigation by the Symantec Threat Hunter Team has produced unprecedented visibility into the activities of Jewelbug (aka Earth Alux, REF7707, CL-STA-0049), a China-based APT group that has been breaking into government…

SECURITY.COM

Publisher

Aug 13, 2026 at 10:07 AM UTC · 12 min de lecture

Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side
NewsLayer editorial artwork

Key Signal

15+ Government webmail tenants hit

Last Updated

il y a 2 mois

Key findings

  • Jewelbug is a China-based hackers-for-hire group that runs parallel operations: espionage against governments and militaries across the Middle East, Southeast Asia and South Asia, and a for-profit cryptocurrency fraud business.
  • Both missions are administered from a single control panel, XG-Web, a browser-centric remote-access and information-stealing framework that turns a victim’s browser into a full remote-control channel and reaches from there into the host and the internal network behind it.
  • At least one of the operators is tied to a registered Hunan company, and we have identified the sole legal representative by name from government-issued identity documents belonging to the operators.
  • Jewelbug’s main implant is the Antino backdoor. It also operates a malicious Chrome and Firefox extension posing as an application called “PDF Viewer”, paired with a helper disguised as a Microsoft Edge component that gave operators a command shell on the host.
  • In its largest operation, a single planted script placed a watering-hole on more than 15 government webmail tenants in a Middle Eastern country at once.
  • Jewelbug’s victim database recorded more than one million implant check-ins and more than 580,000 stolen browser cookies in less than three months of active operations. One set of implants was configured to utilize the internal proxy of a major U.S. aerospace and industrial manufacturer.