Jewelbug APT Group Engages in Espionage and Cryptocurrency Fraud

Jewelbug APT Group Engages in Espionage and Cryptocurrency Fraud

First seen 13 Aug 2026, 10:51 UTC DarkreadingSecurityCybersecuritynewsCryptobriefingBleepingcomputer+12 77.9

Article Content

Browse articles
ThreatCluster

The Jewelbug APT group, based in China, has been conducting simultaneous cyber espionage and cryptocurrency fraud operations. Utilizing a single command-and-control platform named XG-Web, the group has compromised over 15 government webmail accounts across multiple countries in the Middle East and Asia. Their operations have resulted in the theft of more than 580,000 browser cookies and over 2,300 email bodies. The group employs a malicious browser extension called 'PDF Viewer' that steals sensitive information and can replace cryptocurrency wallet addresses during transactions. Jewelbug's activities have targeted government, military, and telecommunications sectors, indicating a significant scale of operations. The group has registered hundreds of fake cryptocurrency exchange websites, primarily targeting Chinese-speaking victims. Symantec's research highlights that Jewelbug's dual operations blur the lines between state-sponsored espionage and cybercrime for profit.

Key Points: • Jewelbug operates both espionage and cryptocurrency fraud from a single C2 platform. • The group has compromised over 15 government webmail accounts, affecting multiple countries. • Their malicious browser extension can replace cryptocurrency wallet addresses during transactions.

Timeline

2026-08-13
Symantec reports on Jewelbug's activities
Symantec reveals that Jewelbug conducts espionage and cryptocurrency fraud using the same infrastructure, impacting government entities.
Security
2026-08-13
Jewelbug targets government webmail accounts
The group compromised webmail accounts of 15 government tenants in a Middle Eastern country, exfiltrating sensitive data.
BleepingComputer
2026-08-13
Malicious browser extension identified
The 'PDF Viewer' extension used by Jewelbug can steal cookies and replace cryptocurrency wallet addresses.
DarkReading
2026-08-13
Jewelbug's victim database revealed
Symantec reports that Jewelbug's database holds over one million implant check-ins and significant stolen data.
Cryptobriefing