Jewelbug crypto fraud campaign targeting Chinese-speaking users
Campaign
Summary
Hide ▲
Show ▼
The Jewelbug operation ran a financially motivated crypto fraud campaign against Chinese-speaking cryptocurrency users through fake exchange-download websites, broadening the group's activity beyond espionage. The same operators also used decoy documents themed around Taiwanese government organizations, suggesting an additional interest in Taiwan. Shared infrastructure tied the fraud activity to the group's espionage operations, indicating one team was managing both tracks.
Related Happenings
Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud
Threat Actor Meta
H score62
First: 14.08.2026 10:30
Last: 14.08.2026 10:30
Sources 1
How related:
“The two are not separate ventures that happen to share a name: our investigation revealed they are run by the same small team, on shared infrastructure, from one control panel,”
About this happening:
Jewelbug is a China-linked hack-for-hire threat actor using shared XG-Web infrastructure to run espionage and cryptocurrency fraud in parallel. Broadcom’s Sy...
Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud
Threat Actor MetaHow related: “The two are not separate ventures that happen to share a name: our investigation revealed they are run by the same small team, on shared infrastructure, from one control panel,”
About this happening: Jewelbug is a China-linked hack-for-hire threat actor using shared XG-Web infrastructure to run espionage and cryptocurrency fraud in parallel. Broadcom’s Sy...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor Meta
H score62
First: 13.08.2026 21:15
Last: 13.08.2026 21:15
Sources 1
About this happening:
Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor MetaAbout this happening: Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
Jewelbug multi-region government webmail espionage campaign
Campaign
H score56
First: 13.08.2026 21:15
Last: 13.08.2026 21:15
Sources 1
About this happening:
Jewelbug is a China-linked hack-for-hire campaign that paired government and military espionage with cryptocurrency fraud. The operation compromised 15 governmen...
Jewelbug multi-region government webmail espionage campaign
CampaignAbout this happening: Jewelbug is a China-linked hack-for-hire campaign that paired government and military espionage with cryptocurrency fraud. The operation compromised 15 governmen...
Latest development: 14.08.2026 10:54
Broadcom's Symantec and Carbon Black linked Jewelbug's espionage and crypto-fraud operations to XG-Web, a React/Node.js/MySQL control panel used to manage browser-based access, host obfuscated payloads in public Google Docs, and coordinate the com.microsoft.runedge native-messaging host to run operator commands. The analysis also described the malicious PDF Viewer extension for Google Chrome and Mozilla Firefox, and said the campaign targeted government organizations and militaries across the Middle East, Southeast Asia, and South Asia.
U.S. Scam Center Strike Force anti-fraud initiative
Public Sector Action
H score50
First: 04.06.2026 09:06
Last: 04.06.2026 09:06
Sources 1
About this happening:
The U.S. government continued Scam Center Strike Force, an ongoing anti-fraud initiative aimed at dismantling cyber-enabled fraud and pig butchering networks targe...
U.S. Scam Center Strike Force anti-fraud initiative
Public Sector ActionAbout this happening: The U.S. government continued Scam Center Strike Force, an ongoing anti-fraud initiative aimed at dismantling cyber-enabled fraud and pig butchering networks targe...
Timeline
-
14.08.2026 10:30 2 articles · 13d ago
Jewelbug campaign targets Chinese-speaking cryptocurrency users with fake exchange-download websites
Initial DisclosureBroadcom researchers linked Jewelbug to a financially motivated campaign targeting Chinese-speaking cryptocurrency users through fake exchange-download websites, while decoy documents themed around Taiwanese government organizations suggested an additional interest in Taiwan. The same XG-Web infrastructure and shared backend database also tied the fraud activity to Jewelbug’s espionage operations.
Show sources
- Researchers Link 'Jewelbug' Chinese APT to Hack-for-Hire Operations — www.infosecurity-magazine.com — 14.08.2026 10:30
- Researchers Link 'Jewelbug' Chinese APT to Hack-for-Hire Operations — www.infosecurity-magazine.com — 14.08.2026 10:30