A hacking crew that spends its days spying on governments and its nights running fake crypto exchanges sounds like something out of a heist movie. But according to new research from Broadcom’s Symantec Threat Hunter Team, that is exactly the profile of Jewelbug, a China-based hacker-for-hire group now drawing attention for blending state-linked espionage with large-scale Jewelbug crypto fraud operations aimed squarely at everyday cryptocurrency users.
Key takeaways
- Jewelbug is a China-based hacker-for-hire group running parallel espionage and cryptocurrency fraud campaigns from a single command-and-control panel.
- Its crypto scheme relies on AI-generated fake exchange pages and hundreds of lookalike domains impersonating Binance and OKX.
- Symantec found the group also compromised government, military and telecommunications targets across Asia and the Middle East, plus a major US industrial and aerospace manufacturer.
- Researchers uncovered more than 580,000 stolen browser cookie sets and 2,300 exfiltrated email bodies tied to Jewelbug’s operations.
- Symantec’s Dick O’Brien says the scale of the fraud business suggests this is far more than a side hustle for a state-linked actor.
Jewelbug’s Dual Cyber Operations
Jewelbug operates as a mercenary outfit that appears equally comfortable stealing state secrets as it is draining crypto wallets. Symantec’s researchers describe a group that switches between government espionage and cryptocurrency fraud “with the same ease as jumping between browser tabs,” managing both lines of work from one custom-built control panel.
Government Espionage Activities
On the espionage side, Jewelbug has compromised government, military and telecommunications organizations across Asia and the Middle East. Its most notable operation targeted a Middle Eastern government by breaching a shared web hosting platform run by the country’s state-owned telecom and network services provider, rather than attacking individual agencies one by one. Once inside, the attackers planted a script on the webmail platform that quietly enrolled government staff into their tracking system, stole login cookies, and served fake Adobe Flash update prompts hiding malware.
Other campaigns hit navy, police and army intelligence bodies in Southeast Asia, alongside a major US industrial and aerospace manufacturer. By Symantec’s count, the group amassed more than 580,000 full browser cookie sets, roughly 2,300 fully exfiltrated email bodies, and several thousand stolen login credentials, spanning thousands of distinct victims.
Dick O’Brien, principal intelligence analyst for the Symantec Threat Hunter Team, said the pattern points strongly toward China, though he stopped short of drawing a direct line. “Given their location and their targeting, by far the most likely scenario is that they are working for China,” he said, adding that spying on behalf of another government would be “a very risky proposition” for a group like Jewelbug.
Cryptocurrency Fraud Scheme
When it isn’t spying on foreign governments, Jewelbug turns its infrastructure toward ordinary crypto users. Symantec found the group ran a financial fraud business of striking scale, one that O’Brien says is the biggest clue this isn’t a side project. “The sheer scale of the fraud business is the biggest clue,” he said. “They aren’t just making a little extra money by moonlighting.”







