Skip to content
Jewelbug APT: China-Based Govt Espionage and Crypto Fraud Exposed

Jewelbug APT: China-Based Govt Espionage and Crypto Fraud Exposed

Technadu August 14, 2026

Jewelbug (also tracked as Earth Alux, REF7707, and CL-STA-0049), a China-based group, is running espionage and cryptocurrency fraud in parallel. The two missions are operated by the same small team, on shared infrastructure, from a single control panel, switching between them.

The Symantec Threat Hunter Team has published an investigation into Jewelbug, which targeted government ministries across the Middle East, Southeast Asia, and South Asia, focusing on government communications and their hosting providers.

In its largest cyberespionage operation, the APT group compromised a shared web-hosting platform run by a state telecommunications and network services provider, gaining write access and planting a script across more than 15 government webmail tenants at once.

Jewelbug’s victim database holds more than one million implant check-in rows, more than 580,000 stolen browser cookies, several thousand captured credentials, and more than 2,300 exfiltrated email bodies, ” the Symantec report said .

From there, whenever staff logged in to check email, the script enlisted their session into the XG-Web panel, stole their login cookies, and served fake Adobe Flash update prompts that concealed the Antino backdoor and the PDF Viewer extension.

At the core sits XG-Web, a browser-centric remote-access and infostealing platform that allows operators to manage campaigns, collect stolen data, and issue commands across compromised browsers, Windows systems, Linux servers, and network devices.

The group's Antino Windows backdoor and payload behind a wave of malicious HTML Application (HTA) downloaders is also delivered as a fake Adobe Flash or Adobe installer. It uses the Microsoft Graph API as its command-and-control (C2) channel, hiding traffic inside legitimate Microsoft cloud services, and can sideload the "PDF Viewer" extension.

Despite its name, the latter requests sweeping permissions including cookie access, scripting, debugger control, and native messaging, letting operators execute shell commands on the host through a disguised helper component and steal:

Delivery leveraged obfuscated payloads served through public Google Documents, freshly encoded on every request so no two downloads matched, with C2 hostnames disguised as typosquats of resources such as Google Fonts.

While the PDF Viewer extension includes a built-in feature for silently swapping a victim's cryptocurrency address with an attacker-controlled wallet during a transaction, Symantec found no evidence the group has actually deployed that capability during the observed campaign period.

Jewelbug's commercial arm is tied to a registered company in Hunan Province, China , advertising a " -ranking rental" service on Telegram. Symantec linked the SEO arm to a named individual using the handle "paopaodada" (Bubble Boss).

Operators registered hundreds of lookalike domains impersonating the OKX and Binance exchanges through an SEO-poisoning pipeline, boosted with click-fraud bots and AI-generated fake exchange pages.

Other campaigns hit navy, police, and army intelligence bodies in Southeast Asia. Several ClientKing builds were configured to beacon through the internal corporate proxy of a major U.S. aerospace and industrial manufacturer.

SentinelOne said last week that China- and India-linked hackers target Pakistani Police systems . A July report outlined that Mirage Kitten's new malware toolkit was targeting aerospace and defense sectors across the Middle East and Africa.