Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor Meta
Summary
Hide ▲
Show ▼
Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter Team said the group uses XG-Web as a shared control panel for both activity sets, turning a victim browser into a remote-control channel and pivot point into the host and internal network. The actor targets governments and militaries across the Middle East, Southeast Asia, and South Asia, while also pursuing Chinese-speaking crypto users with fake exchange-download portals. The activity spans PDF Viewer browser-extension abuse, Antino and ClientKing tooling, and a watering-hole operation tied to 15 government webmail tenants.
Related Happenings
SilkParasite Central Asia government spear-phishing and DLL-sideloading campaign
Campaign
H score26
First: 19.08.2026 16:12
Last: 19.08.2026 16:12
Sources 1
About this happening:
The SilkParasite campaign is targeting government bodies in Central Asia with spear-phishing and DLL-sideloading intrusion chains, increasing the risk of stealthy...
SilkParasite Central Asia government spear-phishing and DLL-sideloading campaign
CampaignAbout this happening: The SilkParasite campaign is targeting government bodies in Central Asia with spear-phishing and DLL-sideloading intrusion chains, increasing the risk of stealthy...
SilkParasite RAT toolkit activity
Malware Activity
H score22
First: 19.08.2026 16:12
Last: 19.08.2026 16:12
Sources 1
About this happening:
SilkParasite's RAT toolkit now includes seven families, with five previously undocumented implants that broaden its espionage capability and reduce detection expos...
SilkParasite RAT toolkit activity
Malware ActivityAbout this happening: SilkParasite's RAT toolkit now includes seven families, with five previously undocumented implants that broaden its espionage capability and reduce detection expos...
Jewelbug crypto fraud campaign targeting Chinese-speaking users
Campaign
H score45
First: 14.08.2026 10:30
Last: 14.08.2026 10:30
Sources 1
About this happening:
The Jewelbug operation ran a financially motivated crypto fraud campaign against Chinese-speaking cryptocurrency users through fake exchange-download websites, bro...
Jewelbug crypto fraud campaign targeting Chinese-speaking users
CampaignAbout this happening: The Jewelbug operation ran a financially motivated crypto fraud campaign against Chinese-speaking cryptocurrency users through fake exchange-download websites, bro...
Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud
Threat Actor Meta
H score62
First: 14.08.2026 10:30
Last: 14.08.2026 10:30
Sources 1
How related:
"Both missions are administered from a single control panel, XG-Web, a browser-centric remote-access and information-stealing framework that turns a victim's browser into a full remote-control channel and reaches from there into the host and the internal network behind it," Broadcom's Symantec and Carbon Black Threat Hunter Team said.
About this happening:
Jewelbug is a China-linked hack-for-hire threat actor using shared XG-Web infrastructure to run espionage and cryptocurrency fraud in parallel. Broadcom’s Sy...
Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud
Threat Actor MetaHow related: "Both missions are administered from a single control panel, XG-Web, a browser-centric remote-access and information-stealing framework that turns a victim's browser into a full remote-control channel and reaches from there into the host and the internal network behind it," Broadcom's Symantec and Carbon Black Threat Hunter Team said.
About this happening: Jewelbug is a China-linked hack-for-hire threat actor using shared XG-Web infrastructure to run espionage and cryptocurrency fraud in parallel. Broadcom’s Sy...
Jewelbug multi-region government webmail espionage campaign
Campaign
H score56
First: 13.08.2026 21:15
Last: 13.08.2026 21:15
Sources 1
How related:
"In what has been described as the "largest espionage operation" undertaken by the threat actor, a web hosting provider was compromised to inject JavaScript code into a common webmail installation used by multiple ministries associated with a Middle Eastern government."
About this happening:
Jewelbug is a China-linked hack-for-hire campaign that paired government and military espionage with cryptocurrency fraud. The operation compromised 15 governmen...
Jewelbug multi-region government webmail espionage campaign
CampaignHow related: "In what has been described as the "largest espionage operation" undertaken by the threat actor, a web hosting provider was compromised to inject JavaScript code into a common webmail installation used by multiple ministries associated with a Middle Eastern government."
About this happening: Jewelbug is a China-linked hack-for-hire campaign that paired government and military espionage with cryptocurrency fraud. The operation compromised 15 governmen...
Latest development: 14.08.2026 10:54
Broadcom's Symantec and Carbon Black linked Jewelbug's espionage and crypto-fraud operations to XG-Web, a React/Node.js/MySQL control panel used to manage browser-based access, host obfuscated payloads in public Google Docs, and coordinate the com.microsoft.runedge native-messaging host to run operator commands. The analysis also described the malicious PDF Viewer extension for Google Chrome and Mozilla Firefox, and said the campaign targeted government organizations and militaries across the Middle East, Southeast Asia, and South Asia.
Timeline
-
13.08.2026 21:15 3 articles · 13d ago
Jewelbug runs espionage and crypto-fraud operations against government targets
Campaign Scope UpdateJewelbug, also known as Earth Alux and REF7707, combines espionage against government and military organizations with cryptocurrency fraud. The group is described as using a shared control panel for both activity sets, along with AI-generated fake crypto pages, click bots, and a 44-server content-management fleet with lookalike OKX and Binance domains.
Show sources
- Hackers breach govt webmail while running parallel crypto fraud — www.bleepingcomputer.com — 13.08.2026 21:15
- Hackers breach govt webmail while running parallel crypto fraud — www.bleepingcomputer.com — 13.08.2026 21:15
- China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud — thehackernews.com — 14.08.2026 10:54