This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.
Consent Selection
Details
  • Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
  • Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
    • We do not use cookies of this type.

  • Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
    • We do not use cookies of this type.

  • Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
    • We do not use cookies of this type.

  • Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    • __emg_sidPending
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      __emg_vidPending
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      nl-read-countPending
      Maximum Storage Duration: PersistentType: HTML Local Storage
Cookie declaration last updated on 8/12/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.
NewsLayer

Install NewsLayer

Get the app experience — one tap from your home screen, instant loads and breaking-news alerts.

NewsLayer.com
NewsLayer PulseLIVEBTC$62,834-0.93%ETH$1,877-0.41%SOL$75.48-0.96%XRP$1-0.66%DOGE$0.0694-0.93%ADA$0.1801-1.16%Total Cap$2.26T-0.54%Layer Index43 Neutral
BreakingExternal ReportingĐăng 15 giờ trước

Jewelbug crypto fraud exposed: 580,000 stolen cookies behind fake exchanges

A hacking crew that spends its days spying on governments and its nights running fake crypto exchanges sounds like something out of a heist movie. But according to new research from Broadcom’s Symantec Threat Hunter Team, that is…

Jewelbug crypto fraud exposed: 580,000 stolen cookies behind fake exchanges
Publisher Cryptonews.net 5 phút đọc
Image via Cryptonews.net
580,000+Stolen browser cookie sets
2,300Exfiltrated email bodies
44Content management servers
HundredsLookalike exchange domains

Why This Matters

The scale of stolen browser sessions and credentials could enable account takeovers, targeted phishing and fraud well beyond the initial crypto victims. Impersonation of major exchanges and a browser extension capable of altering wallet addresses suggests users and platforms face a persistent transaction-integrity risk, while the overlap with government espionage raises broader counterparty and infrastructure-security concerns.

Security Context

Affected ecosystemCrypto exchanges and browser credential theft
Affected providersBinance · OKX

Layer Index

43

↓ 1 pts in 24h

A hacking crew that spends its days spying on governments and its nights running fake crypto exchanges sounds like something out of a heist movie. But according to new research from Broadcom’s Symantec Threat Hunter Team, that is exactly the profile of Jewelbug, a China-based hacker-for-hire group now drawing attention for blending state-linked espionage with large-scale Jewelbug crypto fraud operations aimed squarely at everyday cryptocurrency users.

Key takeaways

  • Jewelbug is a China-based hacker-for-hire group running parallel espionage and cryptocurrency fraud campaigns from a single command-and-control panel.
  • Its crypto scheme relies on AI-generated fake exchange pages and hundreds of lookalike domains impersonating Binance and OKX.
  • Symantec found the group also compromised government, military and telecommunications targets across Asia and the Middle East, plus a major US industrial and aerospace manufacturer.
  • Researchers uncovered more than 580,000 stolen browser cookie sets and 2,300 exfiltrated email bodies tied to Jewelbug’s operations.
  • Symantec’s Dick O’Brien says the scale of the fraud business suggests this is far more than a side hustle for a state-linked actor.

Jewelbug’s Dual Cyber Operations

Jewelbug operates as a mercenary outfit that appears equally comfortable stealing state secrets as it is draining crypto wallets. Symantec’s researchers describe a group that switches between government espionage and cryptocurrency fraud “with the same ease as jumping between browser tabs,” managing both lines of work from one custom-built control panel.

Government Espionage Activities

On the espionage side, Jewelbug has compromised government, military and telecommunications organizations across Asia and the Middle East. Its most notable operation targeted a Middle Eastern government by breaching a shared web hosting platform run by the country’s state-owned telecom and network services provider, rather than attacking individual agencies one by one. Once inside, the attackers planted a script on the webmail platform that quietly enrolled government staff into their tracking system, stole login cookies, and served fake Adobe Flash update prompts hiding malware.

Other campaigns hit navy, police and army intelligence bodies in Southeast Asia, alongside a major US industrial and aerospace manufacturer. By Symantec’s count, the group amassed more than 580,000 full browser cookie sets, roughly 2,300 fully exfiltrated email bodies, and several thousand stolen login credentials, spanning thousands of distinct victims.

Dick O’Brien, principal intelligence analyst for the Symantec Threat Hunter Team, said the pattern points strongly toward China, though he stopped short of drawing a direct line. “Given their location and their targeting, by far the most likely scenario is that they are working for China,” he said, adding that spying on behalf of another government would be “a very risky proposition” for a group like Jewelbug.

Cryptocurrency Fraud Scheme

When it isn’t spying on foreign governments, Jewelbug turns its infrastructure toward ordinary crypto users. Symantec found the group ran a financial fraud business of striking scale, one that O’Brien says is the biggest clue this isn’t a side project. “The sheer scale of the fraud business is the biggest clue,” he said. “They aren’t just making a little extra money by moonlighting.”

Cryptocurrency Fraud Techniques and Targets

Jewelbug’s crypto operation leans heavily on automation and artificial intelligence to build convincing fake trading sites at scale, then drives traffic to them through manipulated search rankings.

AI-Generated Fake Exchange Pages

The group uses AI tools to generate thousands of phishing pages themed around cryptocurrency, sports betting and other topics, all managed through a fleet of 44 content management servers, according to Symantec. To push these fake pages higher in search results, Jewelbug deploys click-fraud bots and filters out web crawlers with a PHP script, so automated scanners see harmless content while real visitors get funneled toward the malicious pages and, eventually, malware.

One of the group’s more unusual tools is a browser extension disguised as a “PDF Viewer.” Rather than opening documents, it requests sweeping permissions and harvests cookies, session tokens, browsing history and screenshots. It also lets attackers escape the browser sandbox, inject code into any webpage, and even swap a victim’s crypto wallet address for the attacker’s own during a transaction, a feature Symantec says hasn’t been observed in active use yet.

Impersonation of Binance and OKX via Lookalike Domains

The clearest evidence of the group’s ambitions in China hacker espionage-adjacent financial crime is its impersonation campaign against two of the industry’s biggest names. Jewelbug has registered hundreds of lookalike domains built to mimic Binance and OKX, two of the world’s largest cryptocurrency exchanges, in an effort to trick users into handing over credentials or funds through what look like Binance fake exchange sites.

Both exchanges were named specifically as targets in the impersonation scheme, underscoring how attackers increasingly go after the platforms crypto users already trust rather than building fraud from scratch. This kind of brand impersonation matters because it exploits familiarity: users searching for a legitimate exchange login page can land on a near-identical fake without realizing it, especially when those pages rank well in search results thanks to manipulated traffic.

Symantec Threat Hunter Report Findings

All of these findings trace back to the Symantec Threat Hunter report, which pieced together Jewelbug’s infrastructure through a management platform called “XG-Web.” The platform functions much like commercial software-as-a-service tools, letting operators generate malicious code, manage stolen browser data and oversee individual infections from a single dashboard.

XG-Web’s design also reveals something about the group’s internal structure. It uses role-based access controls with superadmin, admin and ordinary user tiers, and lower-level operators can only see the victims they personally infected. Based on this setup, Symantec characterizes Jewelbug as a relatively small team rather than a sprawling operation.

Researchers also point to a broader trend behind groups like Jewelbug. O’Brien noted that reliance on third-party contractors has grown among nation-states, with China representing “the main growth area,” largely because of the scale at which it wants to operate in cyberspace. That outsourcing model can complicate attribution for defenders, he said, since contracted groups often show “quite an inconsistent pattern of activity.” It can also offer states a layer of plausible deniability, though it comes with tradeoffs. “You have less oversight over operations,” O’Brien said, noting that financially motivated hackers tend to have weaker operational security, “as evidenced by Jewelbug, who left a trail of evidence behind them.”

That trail is precisely what let Symantec map the group’s tools, infrastructure and victims in such detail, and it’s a reminder that even sophisticated dual-purpose operations can unravel once researchers start pulling on the right thread.

FAQ

Who is Jewelbug?

Jewelbug is a China-based hacker-for-hire group conducting cyber espionage and cryptocurrency fraud.

What types of operations does Jewelbug run?

Jewelbug simultaneously conducts government espionage and cryptocurrency fraud operations, managing both from a single custom command-and-control panel.

How does Jewelbug carry out its cryptocurrency fraud?

The group uses AI-generated fake exchange pages and hundreds of lookalike domains impersonating Binance and OKX, boosting their visibility with click-fraud bots and search manipulation.

Which cryptocurrency exchanges were targeted by Jewelbug’s fraud attempts?

Binance and OKX were specifically targeted through impersonation with fake domains designed to look like their legitimate platforms.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

Tin Nóng

Đừng bỏ lỡ tin nóng nào

Reader Poll

Will authorities identify those behind the Jewelbug crypto fraud in the near term?

1 vote

Advertisement

House — Advertise on NewsLayer
NewsLayerAd

Sourced by

Originally reported by Cryptonews.net

NewsLayer coverage based on externally reported material.

The Daily Brief

The onchain economy, before your day starts.

Curated markets, onchain insights, and key headlines — delivered every weekday morning.

Weekdays · Free · ~5 minute read

Tin Liên Quan