Chinese Hackers Run Dual Operations: Espionage and Crypto Fraud
A well-rounded Chinese hacking group targets foreign governments and Chinese-speaking victims alike, researchers found - espionage by day, cryptocurrency fraud business on the side.
GovInfoSecurity
Publisher
Aug 13, 2026 at 10:29 AM UTC · 3 dk okuma

Key Signal
1M+ implant check-in rows
Last Updated
2 ay önce
Chinese Hackers Run Dual Operations: Espionage and Crypto Fraud
A well-rounded Chinese hacking group targets foreign governments and Chinese-speaking victims alike, researchers found - espionage by day, cryptocurrency fraud business on the side.
The threat actor, tracked as Jewelbug or Earth Alux, operates attacks against governments and militaries in Asia and the Middle East, as well as commits for-profit crypto theft from the same control panel with a single victim database, threat intelligence firm Symantec said.
Hackers for hire are quite common in the Chinese cyber ecosystem, Dick O'Brien, principal intelligence analyst on this research, told ISMG. "While many nation states prefer to keep everything in-house, China appears to be operating at such a scale in cyberspace that they need to meet that capacity with contractors," he said (see: Chinese Data Leak Reveals Salt Typhoon Contractors).
The group's commercial arm is tied to a registered company in the inland Chinese province of Hunan. It is registered as a "search-ranking rental" provider and advertised as such on Telegram. It actually is a search-engine-optimization poisoning pipeline that generates phishing pages with artificial intelligence tools, Symantec said.
Article Intelligence
Topics
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
