Jewelbug Runs Government Espionage and Crypto Fraud on Shared Infrastructure
The Chinese threat group Jewelbug has repurposed a single piece of infrastructure to serve two distinct objectives simultaneously: surveilling government organizations and profiting from cryptocurrency fraud. Symantec researchers determined that a small team managed both operations through a shared system, and the resulting database contained traces of thousands of compromised devices.
A Dual-Purpose Threat Actor Targeting Government and Crypto Users
Jewelbug, also tracked under the aliases Earth Alux, REF7707, and CL-STA-0049, has targeted government and military organizations across the Middle East, Southeast Asia, and South Asia. Within specific target lists, researchers identified more than 90 email addresses belonging to police departments and government agencies. In parallel, the same operators lured Chinese-speaking cryptocurrency holders toward fraudulent exchange websites.
XG-Web: The Central Hub of Jewelbug’s Infrastructure
The platform XG-Web served as the operational core of the entire scheme. A malicious “PDF Viewer” browser extension, distributed for both Chrome and Firefox, gained access to cookies, browsing history, bookmarks, clipboard content, and network requests. Operators could execute scripts on any open page and intercept credentials directly. The extension’s code also included a function designed to swap copied cryptocurrency wallet addresses – though this capability was not actively deployed during the attacks Symantec examined.
Beyond the Browser: Antino Backdoor and ClientKing Malware
To operate beyond the confines of the browser, Jewelbug deployed a supplementary Windows utility disguised as a Microsoft Edge component, enabling arbitrary command execution on the compromised system. A separate tool, the Antino backdoor, was distributed disguised as Adobe installers and communicated with command-and-control infrastructure through the Microsoft Graph API. For servers and network equipment, the group developed 37 distinct variants of a Rust-based malware family called ClientKing.
The Scale of the Operation
The scope of Jewelbug’s activity proved unusually large. Over a period of less than three months, the group’s database recorded more than 1 million connection attempts, and the attackers harvested over 580,000 stolen browser cookies. They also collected several thousand sets of credentials and more than 2,300 email message bodies. Server logs contained approximately 1.1 million location records tied to roughly 4,300 unique IP addresses.
Compromising a Government Webmail Platform at Scale
In one of Jewelbug’s largest documented operations, the group gained access to a shared government webmail platform used across a Middle Eastern country. Rather than attacking each government agency separately, the attackers injected a malicious script into the platform’s shared service template. As a result, the malicious code simultaneously appeared across more than 15 separate government email systems. Once an employee logged in, the script harvested their session cookies, while a fraudulent pop-up prompting users to update Adobe Flash facilitated the installation of the Antino backdoor.
The Commercial Side: Fake Crypto Exchange Websites
In parallel, the same team operated a commercial scheme built around counterfeit cryptocurrency exchange websites. An automated system generated thousands of pages mimicking OKX and Binance, while more than 40 servers and dedicated software tools helped push those fraudulent pages higher in search engine rankings. Symantec traced the commercial branch of this infrastructure back to a registered company in China’s Hunan province. Based on their assessment, researchers concluded that Jewelbug more closely resembles a contract-based hacking team – one that blends state-directed cyber espionage with an independent criminal business on the side.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.