Find notable cyber news and cases, enriched with sources, timelines, and signals.

Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud

Threat Actor Meta
First reported
Last updated
Happening score
H score 62
2 unique sources, 2 articles

Summary

Hide ▲

Jewelbug is a China-linked hack-for-hire threat actor using shared XG-Web infrastructure to run espionage and cryptocurrency fraud in parallel. Broadcom’s Symantec and Carbon Black Threat Hunter Team said the group targets governments and militaries across the Middle East, Southeast Asia, and South Asia, while also running fraud against Chinese-speaking cryptocurrency users. The operation uses a browser-centric control panel, malicious browser extensions, and backend tooling that spans Windows, Linux, and network devices. Researchers also tied the activity to a broader toolset including Antino, ClientKing, and payload delivery through Google Docs.

Related Happenings

PaperCut customer confirmed compromise incidents

Incident
H score36 First: 27.08.2026 19:31 Last: 27.08.2026 19:31 Sources 1

About this happening: PaperCut customers are facing confirmed compromise incidents tied to actively exploited PaperCut NG and PaperCut MF servers, putting exposed deployments at immedia...

QTFY US government and critical infrastructure targeting campaign

Campaign
H score38 First: 27.08.2026 15:00 Last: 27.08.2026 15:00 Sources 1

About this happening: The FBI warned that QTFY is actively targeting US government and critical infrastructure systems with a custom-built intrusion ecosystem, increasing the risk of stealthy c...

UAT-10147 global web-server intrusion campaign

Campaign
H score49 First: 24.08.2026 11:08 Last: 24.08.2026 11:08 Sources 1

About this happening: The UAT-10147 campaign is actively targeting Windows and Linux web servers worldwide, using publicly disclosed vulnerabilities to gain initial access and maintain pers...

SilkParasite Central Asia government spear-phishing and DLL-sideloading campaign

Campaign
H score26 First: 19.08.2026 16:12 Last: 19.08.2026 16:12 Sources 1

About this happening: The SilkParasite campaign is targeting government bodies in Central Asia with spear-phishing and DLL-sideloading intrusion chains, increasing the risk of stealthy...

Jewelbug crypto fraud campaign targeting Chinese-speaking users

Campaign
H score45 First: 14.08.2026 10:30 Last: 14.08.2026 10:30 Sources 1

How related: “The Broadcom researchers said the group operated a financially motivated campaign targeting Chinese-speaking cryptocurrency users through fake exchange-download websites, while decoy documents themed around Taiwanese government organizations suggested it also had an interest in Taiwan.”

About this happening: The Jewelbug operation ran a financially motivated crypto fraud campaign against Chinese-speaking cryptocurrency users through fake exchange-download websites, bro...

Timeline

  1. 14.08.2026 10:30 3 articles · 13d ago

    Jewelbug shares XG-Web infrastructure across espionage and crypto fraud

    Initial Disclosure

    Broadcom's Threat Hunter Team disclosed that Jewelbug, also tracked as Ink Dragon, Earth Alux, REF770 and CL-STA-0049, runs a dual-use operation on shared XG-Web infrastructure that combines espionage against governments and militaries in the Middle East, Southeast Asia and South Asia with a crypto-fraud campaign against Chinese-speaking cryptocurrency users. The same ecosystem used vulnerable IIS and SharePoint servers, web shells, VARGEIT, Squidoor or FinalDraft, Antino, ClientKing, a malicious PDF Viewer extension, Microsoft Graph/Outlook APIs, DNS tunnelling, ICMP tunnelling and Google Docs payload delivery.

    Show sources