Jewelbug: State-Sponsored Espionage Meets Industrial-Scale Crypto Fraud
The **Jewelbug** hacker group, also known as **Earth Alux** and **REF7707**, is operating a sophisticated dual-pronged attack strategy: conducting state-sponsored espionage against government and military targets while simultaneously running an extensive cryptocurrency fraud enterprise. This unusual combination of objectives highlights a potential 'hack-for-hire' model, blurring the lines between nation-state actors and financially motivated cybercriminals.
A recent investigation by **Symantec** has unveiled the complex operations of the China-based hacker group, **Jewelbug**. Their activities span from compromising critical government webmail infrastructure to orchestrating large-scale cryptocurrency scams, all managed from a unified control panel.
### Webmail Compromise Targets Government Agencies
In a notable espionage campaign, **Jewelbug** gained write access to a shared webmail installation used by 15 government tenants in a Middle Eastern country. The attackers injected a malicious script into a common template, ensuring its execution on login pages and mailbox views across the targeted domains.
.jpg)
Upon execution, the script established a **WebSocket** connection to the attacker's command-and-control (**C2**) server. It exfiltrated webmail cookies and user email addresses to identify high-value government targets. These targets were then prompted with a fake **Adobe Flash** update, which deployed the primary payload: the **Antino** backdoor and additional browser tooling.
### Advanced Tooling and Parallel Operations
Beyond **Antino**, **Jewelbug** leverages the **XG-Web** remote-access and data-theft framework for campaign management and victim information. The group delivers **Antino** via malicious **HTA** files and deceptive **Adobe Flash/Adobe** installers, using it to deploy further payloads.

One such payload is a malicious browser extension for **Chrome** and **Firefox**, named **PDF Viewer**. This extension is capable of stealing cookies and credentials, intercepting traffic, injecting JavaScript, and remotely exposing browser functions.

**Symantec**'s deep dive into **Jewelbug**'s infrastructure provided unprecedented visibility into the group's **C2** management platform, database, server logs, source code, and operator files. This revealed the extent of their operations, which include over one million implant check-in rows, more than 580,000 stolen browser cookies, thousands of captured credentials, and over 2,300 exfiltrated email bodies.
### Global Espionage and Automated Crypto Fraud
The espionage component of **Jewelbug**'s activities targets government and military organizations across the Middle East, Southeast Asia, and South Asia. **Symantec** recorded approximately 1.1 million geolocation events from around 4,300 distinct source IP addresses, indicating widespread targeting of state telecom, military networks, and government ministry infrastructure.
Crucially, **Jewelbug**'s financially motivated cryptocurrency theft operations run in parallel. These are supported by an automated attack pipeline that scrapes keywords, generates thousands of AI-powered fake download pages, and publishes them across a 44-server content-management fleet. Hundreds of lookalike domains impersonating legitimate exchanges like **OKX** and **Binance** are used, with click-fraud bots manipulating search rankings to promote their fraudulent sites.

The fraud extends to other lures, including sports betting, pirated livestream portals, and private detective scams. **Symantec** attributes these financially motivated activities with high confidence to a Chinese company advertising SEO services.
### Linux and Router Targeting with ClientKing
**Jewelbug** also employs a Rust-based implant named **ClientKing**, which targets **Linux** servers, **ARM64** devices, and **ASUS** routers. **ClientKing** supports command execution, SOCKS proxying, DNS tunneling, and in-memory kernel module loading. The group cleverly uses public **Google Docs** to host obfuscated payloads, allowing malicious traffic to blend in with legitimate Google services.
**Symantec** has released indicators of compromise (IoCs) and a detailed technical report to assist organizations in detecting and mitigating **Jewelbug**'s activity.