Chinese Hackers-for-Hire Balance State Espionage with Cryptocurrency Heists
A sophisticated group of hackers operating out of China has been caught using a single platform to carry out both state-sponsored cyber espionage and financially motivated cryptocurrency theft. Dubbed “Jewelbug” by researchers, this mercenary group is unlike any other, combining the tactics and techniques (TTPs) of a nation-state with those of a common cybercrime gang.
Jewelbug’s operations rely on a custom command-and-control (C2) panel called XG-Web, which allows the group to manage hundreds of fake cryptocurrency exchanges, as well as compromise government, military, and telecommunications organizations in Asia and the Middle East. What’s striking about Jewelbug is its ability to seamlessly switch between these two distinct lines of business, using a browser extension called “PDF Viewer” that can steal sensitive data from victims’ browsers.
This tool is particularly noteworthy for its versatility, allowing attackers to not only siphon off valuable information but also inject arbitrary JavaScript code into web pages and interact with the victim’s browser as if they were sitting in their chair. Jewelbug has also been observed using AI to generate thousands of phishing websites, managed by a fleet of 44 content management servers.
The group’s internal structure is similarly impressive, with role-based access controls defining superadmins, admins, and ordinary users. This organizational setup suggests that Jewelbug is a relatively small team, but one with a clear division of labor and expertise. The fact that they’re able to manage both espionage and financial operations from the same platform raises questions about their ultimate goal: are they simply looking to maximize profits, or do they have a broader agenda?
Symantec’s analysis highlights the sheer scale of Jewelbug’s cryptocurrency theft business, which is unlike anything seen in traditional state-sponsored cybercrime. This suggests that the group may be receiving support from a nation-state, although it’s unclear whether this is China itself or another country.
Jewelbug’s victims are just as varied as their operations, with government agencies, military organizations, and corporate entities all falling prey to their attacks. Perhaps most concerning is the group’s ability to compromise shared web hosting platforms, using these to plant malware that can enlist entire groups of employees in their XG-Web panel.
For individuals and organizations looking to protect themselves from such threats, it’s essential to be aware of the risks posed by Jewelbug and similar groups. This means staying vigilant about online security, keeping software up-to-date, and being cautious when interacting with unfamiliar websites or downloading attachments. By taking these precautions, you can reduce your risk of becoming a victim of Jewelbug’s activities.
Source: Dark Reading — 2026-08-13