15 Government tenants hit by network compromise
Incident
Summary
Hide ▲
Show ▼
The 15 government tenants using a shared webmail installation suffered a webmail compromise that let attackers obtain write access and monitor mailbox activity across login pages and mailbox views. The intrusion exposed browser cookies and enabled selective targeting of government accounts. The compromise was tied to Jewelbug operations running against a country in the Middle East. The event increased the risk of account abuse, follow-on email collection, and broader ministry compromise.
Related Happenings
Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud
Threat Actor Meta
H score62
First: 14.08.2026 10:30
Last: 14.08.2026 10:30
Sources 1
How related:
"Both missions are administered from a single control panel, XG-Web, a browser-centric remote-access and information-stealing framework that turns a victim's browser into a full remote-control channel and reaches from there into the host and the internal network behind it," Broadcom's Symantec and Carbon Black Threat Hunter Team said.
About this happening:
Jewelbug is a China-linked hack-for-hire threat actor using shared XG-Web infrastructure to run espionage and cryptocurrency fraud in parallel. Broadcom’s Sy...
Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud
Threat Actor MetaHow related: "Both missions are administered from a single control panel, XG-Web, a browser-centric remote-access and information-stealing framework that turns a victim's browser into a full remote-control channel and reaches from there into the host and the internal network behind it," Broadcom's Symantec and Carbon Black Threat Hunter Team said.
About this happening: Jewelbug is a China-linked hack-for-hire threat actor using shared XG-Web infrastructure to run espionage and cryptocurrency fraud in parallel. Broadcom’s Sy...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor Meta
H score62
First: 13.08.2026 21:15
Last: 13.08.2026 21:15
Sources 1
How related:
"That toolset serves two missions: espionage attacks against foreign governments and militaries, and for-profit crypto fraud aimed at Chinese-speaking victims."
About this happening:
Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor MetaHow related: "That toolset serves two missions: espionage attacks against foreign governments and militaries, and for-profit crypto fraud aimed at Chinese-speaking victims."
About this happening: Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
Jewelbug multi-region government webmail espionage campaign
Campaign
H score56
First: 13.08.2026 21:15
Last: 13.08.2026 21:15
Sources 1
How related:
"In what has been described as the "largest espionage operation" undertaken by the threat actor, a web hosting provider was compromised to inject JavaScript code into a common webmail installation used by multiple ministries associated with a Middle Eastern government."
About this happening:
Jewelbug is a China-linked hack-for-hire campaign that paired government and military espionage with cryptocurrency fraud. The operation compromised 15 governmen...
Jewelbug multi-region government webmail espionage campaign
CampaignHow related: "In what has been described as the "largest espionage operation" undertaken by the threat actor, a web hosting provider was compromised to inject JavaScript code into a common webmail installation used by multiple ministries associated with a Middle Eastern government."
About this happening: Jewelbug is a China-linked hack-for-hire campaign that paired government and military espionage with cryptocurrency fraud. The operation compromised 15 governmen...
Latest development: 14.08.2026 10:54
Broadcom's Symantec and Carbon Black linked Jewelbug's espionage and crypto-fraud operations to XG-Web, a React/Node.js/MySQL control panel used to manage browser-based access, host obfuscated payloads in public Google Docs, and coordinate the com.microsoft.runedge native-messaging host to run operator commands. The analysis also described the malicious PDF Viewer extension for Google Chrome and Mozilla Firefox, and said the campaign targeted government organizations and militaries across the Middle East, Southeast Asia, and South Asia.
Microsoft 365 AitM phishing campaign using residential proxies
Campaign
H score34
First: 07.08.2026 13:38
Last: 07.08.2026 13:38
Sources 1
About this happening:
An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...
Microsoft 365 AitM phishing campaign using residential proxies
CampaignAbout this happening: An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...
23AndMe hit by network compromise
Incident
H score55
First: 16.07.2026 16:47
Last: 16.07.2026 16:47
Sources 1
About this happening:
23andMe disclosed a credential-stuffing breach that exposed data on 6.9 million customers, including genetic ancestry information. The unauthorized access ran from A...
23AndMe hit by network compromise
IncidentAbout this happening: 23andMe disclosed a credential-stuffing breach that exposed data on 6.9 million customers, including genetic ancestry information. The unauthorized access ran from A...
Latest development: 17.07.2026 17:30
23andMe reached an $18m settlement with a coalition of 42 US attorneys general over the 2023 credential stuffing breach, and the agreement adds new data protection requirements for 23andMe customer data and TTAM Research.
Timeline
-
13.08.2026 21:15 3 articles · 13d ago
Jewelbug compromises 15 government webmail tenants
Initial DisclosureJewelbug, also known as Earth Alux and REF7707, compromised webmail accounts belonging to 15 government tenants in a campaign targeting a country in the Middle East after gaining write access to a shared webmail installation. The injected script ran on login pages and mailbox views, opened a WebSocket to a C2 server, exfiltrated webmail cookies, and checked each user's email address to determine whether it belonged to a targeted government domain.
Show sources
- Hackers breach govt webmail while running parallel crypto fraud — www.bleepingcomputer.com — 13.08.2026 21:15
- Hackers breach govt webmail while running parallel crypto fraud — www.bleepingcomputer.com — 13.08.2026 21:15
- China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud — thehackernews.com — 14.08.2026 10:54