Jewelbug multi-region government webmail espionage campaign
Campaign
Summary
Hide ▲
Show ▼
Jewelbug is a China-linked hack-for-hire campaign that paired government and military espionage with cryptocurrency fraud. The operation compromised 15 government webmail tenants on a shared installation tied to a state telecommunications provider and national services agency, then used a malicious script on login pages and mailbox views to open a WebSocket to an operator C2 and exfiltrate cookies. Broadcom’s Symantec and Carbon Black said the group also used XG-Web, PDF Viewer browser malware, Google Docs payload hosting, and the com.microsoft.runedge native-messaging host to run commands and extend access across Chrome and Firefox. The campaign targeted governments and militaries across the Middle East, Southeast Asia, and South Asia, and Broadcom said the scale included more than 1 million implant check-ins, over 580,000 stolen browser cookies, and more than 2,300 exfiltrated email bodies.
Related Happenings
Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud
Threat Actor Meta
H score62
First: 14.08.2026 10:30
Last: 14.08.2026 10:30
Sources 1
How related:
"Both missions are administered from a single control panel, XG-Web, a browser-centric remote-access and information-stealing framework that turns a victim's browser into a full remote-control channel and reaches from there into the host and the internal network behind it," Broadcom's Symantec and Carbon Black Threat Hunter Team said.
About this happening:
Jewelbug is a China-linked hack-for-hire threat actor using shared XG-Web infrastructure to run espionage and cryptocurrency fraud in parallel. Broadcom’s Sy...
Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud
Threat Actor MetaHow related: "Both missions are administered from a single control panel, XG-Web, a browser-centric remote-access and information-stealing framework that turns a victim's browser into a full remote-control channel and reaches from there into the host and the internal network behind it," Broadcom's Symantec and Carbon Black Threat Hunter Team said.
About this happening: Jewelbug is a China-linked hack-for-hire threat actor using shared XG-Web infrastructure to run espionage and cryptocurrency fraud in parallel. Broadcom’s Sy...
Jewelbug crypto fraud campaign targeting Chinese-speaking users
Campaign
H score45
First: 14.08.2026 10:30
Last: 14.08.2026 10:30
Sources 1
About this happening:
The Jewelbug operation ran a financially motivated crypto fraud campaign against Chinese-speaking cryptocurrency users through fake exchange-download websites, bro...
Jewelbug crypto fraud campaign targeting Chinese-speaking users
CampaignAbout this happening: The Jewelbug operation ran a financially motivated crypto fraud campaign against Chinese-speaking cryptocurrency users through fake exchange-download websites, bro...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor Meta
H score62
First: 13.08.2026 21:15
Last: 13.08.2026 21:15
Sources 1
How related:
"That toolset serves two missions: espionage attacks against foreign governments and militaries, and for-profit crypto fraud aimed at Chinese-speaking victims."
About this happening:
Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor MetaHow related: "That toolset serves two missions: espionage attacks against foreign governments and militaries, and for-profit crypto fraud aimed at Chinese-speaking victims."
About this happening: Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
15 Government tenants hit by network compromise
Incident
H score50
First: 13.08.2026 21:15
Last: 13.08.2026 21:15
Sources 1
How related:
In a recent operation, Jewelbug (also known as Earth Alux and REF7707) compromised webmail accounts belonging to 15 government tenants as part of a campaign targeting a country in the Middle East.
About this happening:
The 15 government tenants using a shared webmail installation suffered a webmail compromise that let attackers obtain write access and monitor mailbox activity acr...
15 Government tenants hit by network compromise
IncidentHow related: In a recent operation, Jewelbug (also known as Earth Alux and REF7707) compromised webmail accounts belonging to 15 government tenants as part of a campaign targeting a country in the Middle East.
About this happening: The 15 government tenants using a shared webmail installation suffered a webmail compromise that let attackers obtain write access and monitor mailbox activity acr...
Microsoft 365 AitM phishing campaign using residential proxies
Campaign
H score34
First: 07.08.2026 13:38
Last: 07.08.2026 13:38
Sources 1
About this happening:
An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...
Microsoft 365 AitM phishing campaign using residential proxies
CampaignAbout this happening: An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...
Timeline
-
14.08.2026 10:54 1 articles · 12d ago
Broadcom details XG-Web tooling behind Jewelbug espionage and crypto fraud
Technical Analysis UpdateBroadcom's Symantec and Carbon Black linked Jewelbug's espionage and crypto-fraud operations to XG-Web, a React/Node.js/MySQL control panel used to manage browser-based access, host obfuscated payloads in public Google Docs, and coordinate the com.microsoft.runedge native-messaging host to run operator commands. The analysis also described the malicious PDF Viewer extension for Google Chrome and Mozilla Firefox, and said the campaign targeted government organizations and militaries across the Middle East, Southeast Asia, and South Asia.
Show sources
- China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud — thehackernews.com — 14.08.2026 10:54
-
13.08.2026 21:15 2 articles · 13d ago
Jewelbug compromises 15 government webmail tenants across multiple regions
Initial DisclosureJewelbug, also known as Earth Alux and REF7707, compromised webmail accounts belonging to 15 government tenants after gaining write access to a shared webmail installation on a platform operated by a state telecommunications provider and national services agency. The same operation targeted government and military organizations across the Middle East, Southeast Asia, and South Asia, used a malicious script on login pages and mailbox views to open a WebSocket to the operator C2, and overlapped with parallel cryptocurrency fraud activity run from the same control panel.
Show sources
- Hackers breach govt webmail while running parallel crypto fraud — www.bleepingcomputer.com — 13.08.2026 21:15
- Hackers breach govt webmail while running parallel crypto fraud — www.bleepingcomputer.com — 13.08.2026 21:15