Skip to content
Jewelbug APT Group Engages in Espionage and Cryptocurrency Fraud

Jewelbug APT Group Engages in Espionage and Cryptocurrency Fraud

First seen 13 Aug 2026, 10:51 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster August 14, 2026 at 10:48 UTC
  • Jewelbug operates both espionage and cryptocurrency fraud from a single C2 platform.
  • The group has compromised over 15 government webmail accounts, affecting multiple countries.
  • Their malicious browser extension can replace cryptocurrency wallet addresses during transactions.

The Jewelbug APT group, based in China, has been conducting simultaneous cyber espionage and cryptocurrency fraud operations. Utilizing a single command-and-control platform named XG-Web, the group has compromised over 15 government webmail accounts across multiple countries in the Middle East and Asia. Their operations have resulted in the theft of more than 580,000 browser cookies and over 2,300 email bodies. The group employs a malicious browser extension called 'PDF Viewer' that steals sensitive information and can replace cryptocurrency wallet addresses during transactions. Jewelbug's activities have targeted government, military, and telecommunications sectors, indicating a significant scale of operations. The group has registered hundreds of fake cryptocurrency exchange websites, primarily targeting Chinese-speaking victims. Symantec's research highlights that Jewelbug's dual operations blur the lines between state-sponsored espionage and cybercrime for profit.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 30d ago How this analysis works

Timeline

2026-08-13
Symantec reports on Jewelbug's activities
Symantec reveals that Jewelbug conducts espionage and cryptocurrency fraud using the same infrastructure, impacting government entities.
Security
2026-08-13
Jewelbug targets government webmail accounts
The group compromised webmail accounts of 15 government tenants in a Middle Eastern country, exfiltrating sensitive data.
BleepingComputer
2026-08-13
Malicious browser extension identified
The 'PDF Viewer' extension used by Jewelbug can steal cookies and replace cryptocurrency wallet addresses.
DarkReading
2026-08-13
Jewelbug's victim database revealed
Symantec reports that Jewelbug's database holds over one million implant check-ins and significant stolen data.
Cryptobriefing

More articles in this cluster (18)

Following this threat?

Track Cl-sta-0049, Antino and Center For Strategic And International Studies in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed