www.security.com
Jewelbug APT Group Engages in Espionage and Cryptocurrency Fraud
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Symantec Threat Hunter Team has uncovered the activities of Jewelbug, a China-based APT group involved in cyber espionage and cryptocurrency fraud. Operating from a shared infrastructure, the group targets government ministries across Asia and the Middle East while simultaneously running a fraudulent cryptocurrency exchange business. Their operations utilize a custom command-and-control platform and a variety of malware, including a malicious browser extension named 'PDF Viewer' that steals sensitive data. The group has compromised over 90 police and government email addresses in South Asia and has developed multiple malware implants for espionage and financial theft. Their activities suggest a significant scale of operations, with hundreds of fake exchanges and a focus on Chinese-speaking victims. The investigation highlights the dual nature of their operations, combining state-sponsored espionage with financially motivated cybercrime.
Key Points: • Jewelbug operates both espionage and cryptocurrency fraud from a single control panel. • The group has targeted over 90 government and police email addresses in South Asia. • Their primary malware, 'PDF Viewer', steals sensitive data and allows extensive browser manipulation.