Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud
Threat Actor Meta
Summary
Hide ▲
Show ▼
Jewelbug is a China-linked hack-for-hire threat actor using shared XG-Web infrastructure to run espionage and cryptocurrency fraud in parallel. Broadcom’s Symantec and Carbon Black Threat Hunter Team said the group targets governments and militaries across the Middle East, Southeast Asia, and South Asia, while also running fraud against Chinese-speaking cryptocurrency users. The operation uses a browser-centric control panel, malicious browser extensions, and backend tooling that spans Windows, Linux, and network devices. Researchers also tied the activity to a broader toolset including Antino, ClientKing, and payload delivery through Google Docs.
Related Happenings
PaperCut customer confirmed compromise incidents
Incident
H score36
First: 27.08.2026 19:31
Last: 27.08.2026 19:31
Sources 1
About this happening:
PaperCut customers are facing confirmed compromise incidents tied to actively exploited PaperCut NG and PaperCut MF servers, putting exposed deployments at immedia...
PaperCut customer confirmed compromise incidents
IncidentAbout this happening: PaperCut customers are facing confirmed compromise incidents tied to actively exploited PaperCut NG and PaperCut MF servers, putting exposed deployments at immedia...
QTFY US government and critical infrastructure targeting campaign
Campaign
H score38
First: 27.08.2026 15:00
Last: 27.08.2026 15:00
Sources 1
About this happening:
The FBI warned that QTFY is actively targeting US government and critical infrastructure systems with a custom-built intrusion ecosystem, increasing the risk of stealthy c...
QTFY US government and critical infrastructure targeting campaign
CampaignAbout this happening: The FBI warned that QTFY is actively targeting US government and critical infrastructure systems with a custom-built intrusion ecosystem, increasing the risk of stealthy c...
UAT-10147 global web-server intrusion campaign
Campaign
H score49
First: 24.08.2026 11:08
Last: 24.08.2026 11:08
Sources 1
About this happening:
The UAT-10147 campaign is actively targeting Windows and Linux web servers worldwide, using publicly disclosed vulnerabilities to gain initial access and maintain pers...
UAT-10147 global web-server intrusion campaign
CampaignAbout this happening: The UAT-10147 campaign is actively targeting Windows and Linux web servers worldwide, using publicly disclosed vulnerabilities to gain initial access and maintain pers...
SilkParasite Central Asia government spear-phishing and DLL-sideloading campaign
Campaign
H score26
First: 19.08.2026 16:12
Last: 19.08.2026 16:12
Sources 1
About this happening:
The SilkParasite campaign is targeting government bodies in Central Asia with spear-phishing and DLL-sideloading intrusion chains, increasing the risk of stealthy...
SilkParasite Central Asia government spear-phishing and DLL-sideloading campaign
CampaignAbout this happening: The SilkParasite campaign is targeting government bodies in Central Asia with spear-phishing and DLL-sideloading intrusion chains, increasing the risk of stealthy...
Jewelbug crypto fraud campaign targeting Chinese-speaking users
Campaign
H score45
First: 14.08.2026 10:30
Last: 14.08.2026 10:30
Sources 1
How related:
“The Broadcom researchers said the group operated a financially motivated campaign targeting Chinese-speaking cryptocurrency users through fake exchange-download websites, while decoy documents themed around Taiwanese government organizations suggested it also had an interest in Taiwan.”
About this happening:
The Jewelbug operation ran a financially motivated crypto fraud campaign against Chinese-speaking cryptocurrency users through fake exchange-download websites, bro...
Jewelbug crypto fraud campaign targeting Chinese-speaking users
CampaignHow related: “The Broadcom researchers said the group operated a financially motivated campaign targeting Chinese-speaking cryptocurrency users through fake exchange-download websites, while decoy documents themed around Taiwanese government organizations suggested it also had an interest in Taiwan.”
About this happening: The Jewelbug operation ran a financially motivated crypto fraud campaign against Chinese-speaking cryptocurrency users through fake exchange-download websites, bro...
Timeline
-
14.08.2026 10:30 3 articles · 13d ago
Jewelbug shares XG-Web infrastructure across espionage and crypto fraud
Initial DisclosureBroadcom's Threat Hunter Team disclosed that Jewelbug, also tracked as Ink Dragon, Earth Alux, REF770 and CL-STA-0049, runs a dual-use operation on shared XG-Web infrastructure that combines espionage against governments and militaries in the Middle East, Southeast Asia and South Asia with a crypto-fraud campaign against Chinese-speaking cryptocurrency users. The same ecosystem used vulnerable IIS and SharePoint servers, web shells, VARGEIT, Squidoor or FinalDraft, Antino, ClientKing, a malicious PDF Viewer extension, Microsoft Graph/Outlook APIs, DNS tunnelling, ICMP tunnelling and Google Docs payload delivery.
Show sources
- Researchers Link 'Jewelbug' Chinese APT to Hack-for-Hire Operations — www.infosecurity-magazine.com — 14.08.2026 10:30
- Researchers Link 'Jewelbug' Chinese APT to Hack-for-Hire Operations — www.infosecurity-magazine.com — 14.08.2026 10:30
- China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud — thehackernews.com — 14.08.2026 10:54