‘Jewelbug’ APT Balances State Espionage & Cryptocurrency Theft

A Notorious APT Group Juggles State Espionage and Cryptocurrency Theft from the Same Web Panel

Researchers have uncovered a sophisticated mercenary group operating out of China that seamlessly switches between conducting high-stakes cyber espionage on behalf of nation-states and engaging in lucrative cryptocurrency theft. Dubbed “Jewelbug” by Symantec, this advanced persistent threat (APT) group has been observed leveraging a single custom command-and-control (C2) panel to manage both operations.

The sheer scale of Jewelbug’s illicit activities is staggering. In addition to compromising government and military organizations in Asia and the Middle East, the group operates hundreds of fake cryptocurrency exchanges and uses AI to generate thousands of phishing websites on behalf of its clients. What’s more, Jewelbug’s toolset includes a browser extension called “PDF Viewer” that can steal sensitive information such as cookies, session tokens, and even inject arbitrary JavaScript into web pages.

According to Symantec’s research, Jewelbug campaigns rely on three primary malware implants: a Windows backdoor called “Antino,” a Linux backdoor known as “ClientKing,” and the browser extension “PDF Viewer.” The latter is particularly noteworthy for its ability to extract sensitive information from victims’ browsers. While it appears that Jewelbug has not yet used this feature for cryptocurrency theft, it would allow attackers to silently replace a victim’s cryptocurrency address with their own wallet address during a transaction.

One of the most striking aspects of Jewelbug’s operations is its use of a platform called “XG-Web” to manage infections and stolen data. This customizable C2 panel allows group members to generate new malicious code, oversee individual infections, and even segment lower-level operators so they can only view victims they’ve infected.

Jewelbug’s victims include government agencies, military organizations, and corporate entities in the Middle East and Asia. In one notable incident, the group targeted a shared Web hosting platform used by multiple state agencies, compromising their webmail platforms to steal login cookies and enroll them into the XG-Web panel.

What makes Jewelbug so concerning is its ability to balance high-stakes cyber espionage with lucrative cryptocurrency theft from the same operations infrastructure. This blurs the line between traditional nation-state sponsored attacks and financially motivated heists. As Symantec notes, “This is quite different from cases where we’ve seen state-sponsored actors dabbling in cybercrime to make a little extra money.”

The takeaway for organizations is clear: Jewelbug’s existence highlights the need for robust cybersecurity measures that can detect and respond to sophisticated threats from mercenary groups like this. By staying vigilant and updating security protocols regularly, businesses and governments can mitigate the risks posed by APT groups operating in the shadows.


Source: Dark Reading — 2026-08-13