Find notable cyber news and cases, enriched with sources, timelines, and signals.

Jewelbug multi-region government webmail espionage campaign

Campaign
First reported
Last updated
Happening score
H score 56
2 unique sources, 2 articles

Summary

Hide ▲

Jewelbug is a China-linked hack-for-hire campaign that paired government and military espionage with cryptocurrency fraud. The operation compromised 15 government webmail tenants on a shared installation tied to a state telecommunications provider and national services agency, then used a malicious script on login pages and mailbox views to open a WebSocket to an operator C2 and exfiltrate cookies. Broadcom’s Symantec and Carbon Black said the group also used XG-Web, PDF Viewer browser malware, Google Docs payload hosting, and the com.microsoft.runedge native-messaging host to run commands and extend access across Chrome and Firefox. The campaign targeted governments and militaries across the Middle East, Southeast Asia, and South Asia, and Broadcom said the scale included more than 1 million implant check-ins, over 580,000 stolen browser cookies, and more than 2,300 exfiltrated email bodies.

Related Happenings

Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud

Threat Actor Meta
H score62 First: 14.08.2026 10:30 Last: 14.08.2026 10:30 Sources 1

How related: "Both missions are administered from a single control panel, XG-Web, a browser-centric remote-access and information-stealing framework that turns a victim's browser into a full remote-control channel and reaches from there into the host and the internal network behind it," Broadcom's Symantec and Carbon Black Threat Hunter Team said.

About this happening: Jewelbug is a China-linked hack-for-hire threat actor using shared XG-Web infrastructure to run espionage and cryptocurrency fraud in parallel. Broadcom’s Sy...

Jewelbug crypto fraud campaign targeting Chinese-speaking users

Campaign
H score45 First: 14.08.2026 10:30 Last: 14.08.2026 10:30 Sources 1

About this happening: The Jewelbug operation ran a financially motivated crypto fraud campaign against Chinese-speaking cryptocurrency users through fake exchange-download websites, bro...

Jewelbug pairs espionage with industrial-scale cryptocurrency fraud

Threat Actor Meta
H score62 First: 13.08.2026 21:15 Last: 13.08.2026 21:15 Sources 1

How related: "That toolset serves two missions: espionage attacks against foreign governments and militaries, and for-profit crypto fraud aimed at Chinese-speaking victims."

About this happening: Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...

15 Government tenants hit by network compromise

Incident
H score50 First: 13.08.2026 21:15 Last: 13.08.2026 21:15 Sources 1

How related: In a recent operation, Jewelbug (also known as Earth Alux and REF7707) compromised webmail accounts belonging to 15 government tenants as part of a campaign targeting a country in the Middle East.

About this happening: The 15 government tenants using a shared webmail installation suffered a webmail compromise that let attackers obtain write access and monitor mailbox activity acr...

Microsoft 365 AitM phishing campaign using residential proxies

Campaign
H score34 First: 07.08.2026 13:38 Last: 07.08.2026 13:38 Sources 1

About this happening: An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...

Timeline

  1. 14.08.2026 10:54 1 articles · 12d ago

    Broadcom details XG-Web tooling behind Jewelbug espionage and crypto fraud

    Technical Analysis Update

    Broadcom's Symantec and Carbon Black linked Jewelbug's espionage and crypto-fraud operations to XG-Web, a React/Node.js/MySQL control panel used to manage browser-based access, host obfuscated payloads in public Google Docs, and coordinate the com.microsoft.runedge native-messaging host to run operator commands. The analysis also described the malicious PDF Viewer extension for Google Chrome and Mozilla Firefox, and said the campaign targeted government organizations and militaries across the Middle East, Southeast Asia, and South Asia.

    Show sources
  2. 13.08.2026 21:15 2 articles · 13d ago

    Jewelbug compromises 15 government webmail tenants across multiple regions

    Initial Disclosure

    Jewelbug, also known as Earth Alux and REF7707, compromised webmail accounts belonging to 15 government tenants after gaining write access to a shared webmail installation on a platform operated by a state telecommunications provider and national services agency. The same operation targeted government and military organizations across the Middle East, Southeast Asia, and South Asia, used a malicious script on login pages and mailbox views to open a WebSocket to the operator C2, and overlapped with parallel cryptocurrency fraud activity run from the same control panel.

    Show sources