A Sophisticated Hacker Group Combines Espionage with Crypto Fraud
In a brazen display of cybercrime capabilities, the Jewelbug hacker group has been uncovered conducting espionage operations against governments and militaries while simultaneously engaging in large-scale cryptocurrency fraud. The dual-pronged approach not only highlights the group’s advanced technical skills but also raises concerns about the potential for state-sponsored hacking.
Researchers at Symantec have been tracking Jewelbug, also known as Earth Alux and REF7707, which is believed to be based in China. The group has been targeting government agencies and organizations in critical sectors such as defense, telecommunications, education, and aviation across multiple regions, including the Middle East, Southeast Asia, and South Asia.
One of the most significant vulnerabilities exploited by Jewelbug was a shared webmail installation used by multiple government ministries and agencies. By gaining write access to this platform, the group inserted a malicious script into its common template that ran on login pages and mailbox views across 15 tenants. This script established a connection to the attacker’s command-and-control server, exfiltrated webmail cookies, and identified whether the user’s email address belonged to a targeted government domain.
Once a valuable target was identified, the group would deliver a fake Adobe Flash update prompt that installed the main payload on Windows systems – the Antino backdoor. This malware allows Jewelbug to deploy additional payloads, including a malicious browser extension for Chrome and Firefox called PDF Viewer, which steals cookies and credentials, intercepts traffic, injects JavaScript, and remotely exposes browser functions.
Symantec’s investigation revealed that Jewelbug ran a massive espionage operation, with over one million implant check-in rows, more than 580,000 stolen browser cookies, several thousand captured credentials, and over 2,300 exfiltrated email bodies stored in their victim database. The group also engaged in industrial-scale cryptocurrency fraud, using AI-generated articles to drive traffic to fake crypto exchange sites and click-fraud bots that manipulate search rankings.
The researchers noted that the threat actor relies on an automated attack pipeline that scrapes keywords, generates thousands of fake download pages using AI, and publishes them across a 44-server content-management fleet and hundreds of lookalike domains impersonating legitimate exchanges like OKX and Binance. The group also uses click bots to manipulate rankings and promote their fraudulent pages.
The combination of espionage and cryptocurrency fraud highlights the sophistication and adaptability of modern cyber threats. Jewelbug’s capabilities demonstrate that state-sponsored hacking groups can be involved in both espionage and financial gain, making it essential for organizations to stay vigilant against these dual-pronged attacks.
To mitigate this risk, individuals and organizations must prioritize robust security measures, including regular software updates, multi-factor authentication, and employee education on phishing tactics. Additionally, monitoring network traffic and implementing intrusion detection systems can help identify potential threats before they spread. By staying informed and proactive, we can better protect ourselves against these evolving cyber threats.
Source: Bleeping Computer — 2026-08-13