Find notable cyber news and cases, enriched with sources, timelines, and signals.

Jewelbug crypto fraud campaign targeting Chinese-speaking users

Campaign
First reported
Last updated
Happening score
H score 45
1 unique sources, 1 articles

Summary

Hide ▲

The Jewelbug operation ran a financially motivated crypto fraud campaign against Chinese-speaking cryptocurrency users through fake exchange-download websites, broadening the group's activity beyond espionage. The same operators also used decoy documents themed around Taiwanese government organizations, suggesting an additional interest in Taiwan. Shared infrastructure tied the fraud activity to the group's espionage operations, indicating one team was managing both tracks.

Related Happenings

Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud

Threat Actor Meta
H score62 First: 14.08.2026 10:30 Last: 14.08.2026 10:30 Sources 1

How related: “The two are not separate ventures that happen to share a name: our investigation revealed they are run by the same small team, on shared infrastructure, from one control panel,”

About this happening: Jewelbug is a China-linked hack-for-hire threat actor using shared XG-Web infrastructure to run espionage and cryptocurrency fraud in parallel. Broadcom’s Sy...

Jewelbug pairs espionage with industrial-scale cryptocurrency fraud

Threat Actor Meta
H score62 First: 13.08.2026 21:15 Last: 13.08.2026 21:15 Sources 1

About this happening: Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...

Jewelbug multi-region government webmail espionage campaign

Campaign
H score56 First: 13.08.2026 21:15 Last: 13.08.2026 21:15 Sources 1

About this happening: Jewelbug is a China-linked hack-for-hire campaign that paired government and military espionage with cryptocurrency fraud. The operation compromised 15 governmen...

Latest development: 14.08.2026 10:54

Broadcom's Symantec and Carbon Black linked Jewelbug's espionage and crypto-fraud operations to XG-Web, a React/Node.js/MySQL control panel used to manage browser-based access, host obfuscated payloads in public Google Docs, and coordinate the com.microsoft.runedge native-messaging host to run operator commands. The analysis also described the malicious PDF Viewer extension for Google Chrome and Mozilla Firefox, and said the campaign targeted government organizations and militaries across the Middle East, Southeast Asia, and South Asia.

U.S. Scam Center Strike Force anti-fraud initiative

Public Sector Action
H score50 First: 04.06.2026 09:06 Last: 04.06.2026 09:06 Sources 1

About this happening: The U.S. government continued Scam Center Strike Force, an ongoing anti-fraud initiative aimed at dismantling cyber-enabled fraud and pig butchering networks targe...

Timeline

  1. 14.08.2026 10:30 2 articles · 13d ago

    Jewelbug campaign targets Chinese-speaking cryptocurrency users with fake exchange-download websites

    Initial Disclosure

    Broadcom researchers linked Jewelbug to a financially motivated campaign targeting Chinese-speaking cryptocurrency users through fake exchange-download websites, while decoy documents themed around Taiwanese government organizations suggested an additional interest in Taiwan. The same XG-Web infrastructure and shared backend database also tied the fraud activity to Jewelbug’s espionage operations.

    Show sources