Jewelbug APT Group Engages in Espionage and Cryptocurrency Fraud

Jewelbug APT Group Engages in Espionage and Cryptocurrency Fraud

First seen 13 Aug 2026, 10:51 UTC DarkreadingSecuritywww.security.comwww.techtarget.com 89% similarity 75.5

Article Content

Browse articles
ThreatCluster

The Symantec Threat Hunter Team has uncovered the activities of Jewelbug, a China-based APT group involved in cyber espionage and cryptocurrency fraud. Operating from a shared infrastructure, the group targets government ministries across Asia and the Middle East while simultaneously running a fraudulent cryptocurrency exchange business. Their operations utilize a custom command-and-control platform and a variety of malware, including a malicious browser extension named 'PDF Viewer' that steals sensitive data. The group has compromised over 90 police and government email addresses in South Asia and has developed multiple malware implants for espionage and financial theft. Their activities suggest a significant scale of operations, with hundreds of fake exchanges and a focus on Chinese-speaking victims. The investigation highlights the dual nature of their operations, combining state-sponsored espionage with financially motivated cybercrime.

Key Points: • Jewelbug operates both espionage and cryptocurrency fraud from a single control panel. • The group has targeted over 90 government and police email addresses in South Asia. • Their primary malware, 'PDF Viewer', steals sensitive data and allows extensive browser manipulation.

ThreatCluster AI How this analysis works

Timeline

2026-08-13
Jewelbug activities revealed
Symantec's investigation exposes Jewelbug's dual operations in espionage and crypto fraud targeting Asia and the Middle East.
www.security.com
2026-08-13
Malicious browser extension identified
'PDF Viewer' extension is reported to steal cookies, session tokens, and other sensitive data from victims.
Darkreading
2026-08-13
Espionage campaigns detailed
Jewelbug's campaigns have targeted government organizations and military entities across multiple regions.
Security

Community

Browse all →