This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.
Consent Selection
Details
  • Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
  • Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
    • We do not use cookies of this type.

  • Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
    • We do not use cookies of this type.

  • Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
    • We do not use cookies of this type.

  • Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    • __emg_sidPending
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      __emg_vidPending
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      nl-read-countPending
      Maximum Storage Duration: PersistentType: HTML Local Storage
Cookie declaration last updated on 8/12/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.
NewsLayer

Install NewsLayer

Get the app experience — one tap from your home screen, instant loads and breaking-news alerts.

NewsLayer.com
NewsLayer PulseLIVEBTC$62,877-0.86%ETH$1,873-0.64%SOL$75.52-0.91%XRP$1-0.47%DOGE$0.0696-0.65%ADA$0.1817-0.31%Total Cap$2.26T-1.01%Layer Index43 Neutral
External ReportingPublié il y a 12 minutes

China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud

The China-linked threat actor known as Jewelbug has been observed carrying out cyber espionage operations targeting governments and militaries, while simultaneously engaging in cryptocurrency fraud.

China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud
Publisher The Hacker News 5 min de lecture
NewsLayer editorial artwork

Layer Index

43

↓ 1 pts in 24h

The China-linked threat actor known as Jewelbug has been observed carrying out cyber espionage operations targeting governments and militaries, while simultaneously engaging in cryptocurrency fraud.

"Both missions are administered from a single control panel, XG-Web, a browser-centric remote-access and information-stealing framework that turns a victim's browser into a full remote-control channel and reaches from there into the host and the internal network behind it," Broadcom's Symantec and Carbon Black Threat Hunter Team said.

Jewelbug is assessed to be a China-based hackers-for-hire group that runs parallel operations, including espionage against governments and militaries across the Middle East, Southeast Asia and South Asia, and a for-profit cryptocurrency fraud business.

"The group has developed five generations of command-and-control (C&C) code and a family of implants spanning browsers, Windows endpoints, Linux servers and network devices, all of it feeding a single database of victims," Broadcom added. "That toolset serves two missions: espionage attacks against foreign governments and militaries, and for-profit crypto fraud aimed at Chinese-speaking victims."

At least one of the operators is said to be tied to a registered company based in Hunan Province. JewelBug overlaps with threat clusters tucked as CL-STA-0049 (Palo Alto Networks Unit 42), Earth Alux (Trend Micro), and REF7707 (Elastic Security Labs). In October 2025, the hacking group was attributed to a five-month-long intrusion aimed at a Russian IT service provider to deliver malware capable of interfering with the normal functioning of security tools.

Symantec said it unearthed a campaign list following a months-long investigation, with entries highlighting espionage campaigns aimed at government organizations across the Middle East and Southeast Asia, as well as more than 90 police and government email addresses in South Asia.

"The group's separate Linux and router implant enables it to extend its reach into network infrastructure, with a couple of builds configured to beacon through the internal corporate proxy of a major U.S. aerospace and industrial manufacturer," it noted.

In tandem, the threat actor is said to have undertaken a financially motivated operation targeted at Chinese-speaking cryptocurrency users using fake exchange-download portals. The presence of decoy documents impersonating Taiwanese government entities suggests that the targeting also likely extends to Taiwan.

Central to the operations is a browser-centric remote-access and information-stealing platform called XG-Web. Built as a React panel over a Node.js backend and a MySQL database, the tool is described by the developers as a penetration-testing platform that makes use of a scheduled job to check the group's own C&C infrastructure against VirusTotal every 12 hours for swift rotation.

XG-Web also utilizes public Google Docs to host obfuscated payloads that are retrieved and executed by their implants. The payloads are XOR encoded with a random key to ensure that no two payloads are identical. The C&C hostnames are disguised to mimic common resources such as Google Fonts.

The primary implant of choice is a malicious browser extension named "PDF Viewer" that can run on both Google Chrome and Mozilla Firefox. Once installed, it requests a wide array of dangerous permissions to access cookies, the debugger, and native messaging, run scripts, intercept web requests, and monitor downloads across all sites.

The extension grants the ability to run arbitrary JavaScript on any web page, remotely interact with the web browser, and harvest credentials by hooking login forms, cookies, browsing history, bookmarks, screenshots, clipboard, and web traffic.

The clipboard module also functions like a clipper, swapping any copied cryptocurrency wallet address with an attacker's to reroute transactions. That said, no address-replacement rules have been triggered, indicating the clipper functionality was not put to use during the campaign period.

"To escape the browser sandbox, the extension talked to a Windows helper registered as a native-messaging host under the misleading name com.microsoft.runedge, which ran operator commands through the Windows command interpreter and returned the output to the panel," Symantec and Carbon Black said.

Some of the other tools in Jewelbug's arsenal are as follows -

  • Antino, a Windows backdoor that's delivered via malicious HTML Application (HTA) downloaders centered around current geopolitical events, as well as bogus Adobe Flash or Adobe installer from threat actor-controlled domains. Upon execution, the malware uses the Microsoft Graph API for C&C to evade detection and blend in with normal traffic.
  • ClientKing, a Rust implant that targets Linux servers and routers, and uses five C&C channels, including a DNS tunnel, to facilitate interactive shell, SOCKS pivoting, and the ability to load kernel modules directly from memory. A parallel toolkit features a kernel-module rootkit and a malicious authentication module hooked into the secure shell su and sudo to steal credentials.

In what has been described as the "largest espionage operation" undertaken by the threat actor, a web hosting provider was compromised to inject JavaScript code into a common webmail installation used by multiple ministries associated with a Middle Eastern government.

The watering hole campaign spanned 15 government webmail tenants, with the malicious code activating on the login page and every mailbox view to exfiltrate cookies over a WebSocket connection and serve a next-stage payload that checks if the victim email address is among the targeted government domains, the account has not already been compromised, and that the system is running Windows before displaying a fake Adobe Flash update prompt.

Victims who ended up clicking on the update receive Antino as the second-stage executable from a domain managed by the threat actor ("microsoft-flash[.]com"). The downloaded binary also sideloads the "PDF Viewer" extension into the user's browser profile and makes Registry modifications to ensure that the add-on automatically launches on the next launch of the browser.

The scale of the espionage campaign is believed to be vast, having collected more than one million implant check-in rows, over 580,000 stolen browser cookies, several thousand captured credentials, and no less than 2,300 exfiltrated email bodies. Runtime server logs have recorded roughly 1.1 million geolocation events against about 4,300 distinct source IP addresses.

These include -

  • ~87,200 connections from a Southeast Asian country (targeting state telecom and military networks)
  • ~53,100 from a Middle Eastern country (across the national carrier’s ranges, including Starlink-connected addresses in the capital)
  • ~15,000 from a second Southeast Asian country (including government ministry infrastructure)

The financial arm of Jewelbug is operated as a registered Chinese company that advertises a commercial search engine optimization (SEO) service on Telegram. However, it is assessed to be a front for an SEO poisoning scheme that involves a combination of artificial intelligence (AI)-generated fake pages impersonating OKX and Binance, more than 40 content management servers, and click fraud bots that drive search engines to rank those pages.

"What makes Jewelbug notable is the combination of two missions in one set of hands," Symantec and Carbon Black said. "Foreign government and foreign military espionage was run from the same infrastructure, by the same team, as a commodity cryptocurrency fraud business."

"That pairing is the signature of a hack-for-hire entity that is running for-profit crime on the side. The exposure also shows the difference between targeting and compromise."

Dernière Minute

Ne manquez aucune actualité de dernière minute

Advertisement

House — Advertise on NewsLayer
NewsLayerAd

Sourced by

Originally reported by The Hacker News

NewsLayer coverage based on externally reported material.

The Daily Brief

The onchain economy, before your day starts.

Curated markets, onchain insights, and key headlines — delivered every weekday morning.

Weekdays · Free · ~5 minute read

Articles Liés