Hackers breach govt webmail while running parallel crypto fraud

**Malicious Hacker Group Exposes Government Webmail Accounts While Conducting Large-Scale Crypto Fraud**

A sophisticated hacking group has been carrying out a parallel campaign of espionage and cryptocurrency theft, compromising government webmail accounts in multiple countries while simultaneously operating fake crypto exchange sites. The Jewelbug hacker collective, also known as Earth Alux and REF7707, has targeted governments and militaries across the Middle East, Southeast Asia, and South Asia, gaining write access to shared webmail installations and inserting malicious scripts that exfiltrate sensitive information.

The group’s cyberespionage campaign involved compromising a web-hosting platform operated by a state telecommunications provider and national services agency in a country in the Middle East. Jewelbug gained write access to multiple government ministries’ and agencies’ webmail accounts, injecting a single script tag that opened a WebSocket connection to the attacker’s command-and-control server every time a user logged in or viewed their mailbox. This allowed the hackers to steal sensitive information, including email addresses, cookies, and credentials.

But Jewelbug’s activities don’t stop at espionage. The group has also been operating an industrial-scale cryptocurrency theft operation, using AI-generated articles to drive traffic to fake crypto exchange sites and click-fraud bots that manipulate search rankings. According to Symantec researchers, the threat actor relies on an automated attack pipeline that scrapes keywords, generates thousands of fake download pages using AI, and publishes them across a 44-server content-management fleet and hundreds of lookalike domains impersonating OKX and Binance.

The group’s use of Antino backdoor malware allows it to deploy additional payloads, including a malicious browser extension for Chrome and Firefox that steals cookies and credentials, intercepts traffic, injects JavaScript, and remotely exposes browser functions. Symantec has obtained visibility into Jewelbug’s infrastructure, revealing the extent of their operations: over one million implant check-in rows, 580,000 stolen browser cookies, thousands of captured credentials, and more than 2,300 exfiltrated email bodies.

The implications are serious: government agencies and organizations in critical sectors have been compromised, exposing sensitive information to malicious actors. Meanwhile, the public is being targeted with fake crypto exchange sites and click-fraud scams, further fueling the group’s cryptocurrency theft operation.

**What can you do?**

In light of this revelation, it’s essential for governments and organizations to review their webmail security measures and ensure that shared hosting platforms are secure against exploitation. Users should also be cautious when clicking on suspicious links or downloading attachments from unknown sources, as these may contain malware or phishing kits. Additionally, anyone investing in cryptocurrency should exercise extreme caution when dealing with unfamiliar exchange sites or investment opportunities, as they may be part of a larger scam.


Source: Bleeping Computer — 2026-08-13