Back Darkreading 'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft
Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa, the Asia Pacific, Europe, and Latin America.
Researchers discovered hackers-for-hire performing cyber espionage and financially motivated heists from the same Web panel.
Researchers have identified an advanced persistent threat (APT) group for hire in China that performs both international cyber espionage and lowly cryptocurrency theft.
With one hand, the mercenary group "Jewelbug" steals cryptocurrency from ordinary people online. With the other, it takes on jobs that must surely be at the behest of a nation-state, most likely China, according to new research from Symantec. The APT group performs both functions from a single, custom command-and-control (C2) panel, switching back and forth with the same ease as jumping between browser tabs. And it's equally accomplished in both ventures, managing hundreds of fake cryptocurrency exchanges while compromising government, military, and telecommunications organizations in Asia and the Middle East.
"This is quite different to cases where we’ve seen state- actors dabbling in cybercrime to make a little extra money," says Dick O'Brien, principal intelligence analyst for the Symantec Threat Hunter Team. "The sheer scale of the fraud business is the biggest clue. They aren't just making a little extra money by moonlighting."
Jewelbug campaigns rely on three primary, custom malware implants. There's a Windows backdoor, "Antino," and a Linux backdoor, "ClientKing," most often seen in cyber-espionage attacks.
The most interesting item in its toolset is a browser extension called "PDF Viewer," according to Symantec. Instead of providing PDF viewing capabilities, it requests every possible permission from victims and then steals their cookies , session tokens, history, screenshots, traffic, and essentially anything else of value. That's only the beginning, though.
The program also allows attackers to escape the browser sandbox, inject arbitrary JavaScript on any webpage, or interact with the victim's browser as if the attacker were sitting in the victim's chair. Though the attackers haven't utilized it yet, there's even a feature for silently replacing a victim's cryptocurrency address with the attacker's wallet address during a transaction.
PDF Viewer is helpful for both espionage and financial theft. When it's not spying on foreign governments, Jewelbug uses AI to generate thousands of cryptocurrency, sports, betting, and other themed phishing websites, managed by a fleet of 44 content management servers. The attackers boost their fake sites' engine rankings using click-fraud bots, and use a PHP snippet to filter Web crawlers, which get innocuous-ish lure content from intended victims, who get the malware.
Whether spying or stealing, Jewelbug group members manage their various infections from a platform called "XG-Web." The platform is as pretty as your average software-as-a-service (SaaS) program, with tabs to generate new malicious code, manage stolen browser data, oversee individual infections, and more.
XG-Web also betrays the group's internal structure. It's configured with role-based access controls, defining superadmin, admin, and ordinary users. Those lower-level operators are segmented so that they can only view the victims they've infected. Symantec characterizes Jewelbug as a small team.
Jewelbug's most impressive caper involved a Middle Eastern government, according to Symantec's report. Rather than wasting time trying to compromise multiple state agencies individually, the group homed in on a shared Web hosting platform run by the country's state-owned telecommunications provider and network services agency.
The threat actors broke in, got write access to the webmail platform, and planted a script. Thereafter, whenever government staff logged in to view their emails, the script enlisted them in the XG-Web panel, stole their login cookies, and presented them with fake Adobe Flash update prompts that concealed the Antino backdoor and PDF Viewer.
Other campaigns have targeted navy, police, and army intelligence bodies in Southeast Asia, as well as a major US industrial and aerospace manufacturer and other similarly large institutions. By way of scale, researchers found more than 580,000 full browser cookie jars, 2,300 fully exfiltrated email bodies, and several thousand login credentials in Jewelbug's coffers, among other stolen data, representing thousands of distinct victims.
"Given their location and their targeting, by far the most likely scenario is that they are working for China," O'Brien speculates. Jewelbug could be operating at the behest of a Chinese state agency , or pursuing operations of their own initiative in the hopes of selling stolen information to government contacts post facto.
There is no direct evidence of a link between Jewelbug and the People's Republic of China, O'Brien acknowledges, but other possibilities remain unlikely. "Spying for other governments is probably a very risky proposition," he notes.
The line between nation-state threat actors and ostensibly independent cybercrime outfits has never been quite so distinct as the textbooks say. In Russia, prominent cybercriminals are either contracted by the government or at least made to align with its political objectives. In Israel, the surveillance, spyware, and hacking scenes are outgrowths of, and believed to be symbiotic with, the country's military apparatus. In China, malware and infrastructure are shared across boundaries, and select academic institutions and private companies directly service government cyber intelligence.
"Use of third-party contractors has grown a lot among nation-states. There are reports of Iran using them, but the main growth area is China. That’s mainly down to the scale China wants to operate at in cyberspace. They need to recruit third parties to do that," O'Brien explains.
For cyber defenders, he adds, "It can make attribution a little bit harder, since you can see quite an inconsistent pattern of activity from some of these actors. And it probably does have benefits for states in terms of plausible deniability."
He stops short of calling it an effective model for other countries, though, considering the many downsides. "You have less oversight over operations. And financially motivated hackers aren't usually the most trustworthy people," O'Brien says. "Their operational security also tends to be a lot poorer, as evidenced by Jewelbug, who left a trail of evidence behind them."
Nate Nelson is a journalist and award-winning scriptwriter. In addition to Dark Reading he writes for Darknet Diaries, the most popular show in cybersecurity across all media.
He began his career as a freelancer, ghostwriting Forbes and CNBC op-eds for executives in tech and finance. Then he transitioned to journalism at Threatpost, where he covered cybersecurity news and trends. Throughout those years he co-created a cybersecurity podcast, Malicious Life, which in its day climbed into the Top 20 technology podcasts charts on Apple Podcasts and Spotify.
He holds degrees from New York University and Bard College. As a born and bred New Yorker, he enjoys a superiority complex, but is polite enough to keep it to himself.
The State of Cloud Security: The Latest Challenges
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Essential News & Insights from Black Hat USA 2025
The Dos and Don'ts of a Cybersecurity Awareness Month People Actually Remember
Building a Secure AI Strategy for the Enterprise
Is your AppSec program Mythos Ready?
Experts Explain How to Develop a Framework for Cyber-Fraud Fusion
Prevention at Machine Speed: Hunting Beyond Known Detections
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
