Threats

Jewelbug Hackers Breach Govt Webmail, Run Crypto Fraud

August 15, 2026 04:14 · 12 min read
Jewelbug Hackers Breach Govt Webmail, Run Crypto Fraud

The Jewelbug hacker group, also known as Earth Alux and REF7707, has been carrying out espionage operations targeting governments and militaries, while also engaging in cryptocurrency fraud. This China-based hacker group compromised webmail accounts belonging to 15 government tenants as part of a campaign targeting a country in the Middle East.

Jewelbug's Espionage Operations

Researchers at Symantec found that the espionage campaign and the cryptocurrency fraud were conducted from the same control panel. The group gained write access to the shared webmail installation and inserted a malicious script into its common template. The script then ran on login pages and mailbox views across 15 tenants, establishing a WebSocket connection to the attacker's command-and-control (C2) server, exfiltrating webmail cookies, and retrieving the user's email address to determine whether it belonged to a targeted government domain.

Malicious Payloads and Tools

Valuable targets would receive a fake Adobe Flash update prompt, which installs the main payload on Windows, the Antino backdoor, and browser tooling. Apart from Antino, the threat actor also uses the XG-Web remote-access and data-theft framework for managing campaigns and victim information. Symantec traced Antino infections to Jewelbug’s infrastructure and then obtained visibility into the group’s C2 management platform, database, server logs, source code, and operator files.

The data showed that the hackers ran a large-scale espionage operation and "an industrial-scale cryptocurrency fraud business." The group's victim database holds more than one million implant check-in rows, more than 580,000 stolen browser cookies, several thousand captured credentials, and more than 2,300 exfiltrated email bodies.

Cryptocurrency Fraud Operations

The cryptocurrency theft operations are backed by AI-generated articles driving traffic to fake crypto exchange sites and click-fraud bots that manipulate search rankings. Jewelbug relies on an automated attack pipeline that scrapes keywords, generates thousands of fake download pages using AI, and publishes them "across a 44-server content-management fleet and hundreds of lookalike domains" impersonating OKX and Binance.

Using click bots, Jewelbug manipulates rankings to promote their fraudulent pages. The fraud uses other lures, as well: sports betting, pirated livestream portals, and private detective scams. Symantec researchers have high confidence attributing Jewelbug's financially-motivated activities to a Chinese company that advertises SEO services.

Other Tools and Techniques

Jewelbug also uses a Rust-based implant called ‘ClientKing’ that targets Linux servers, ARM64 devices, and ASUS routers, and supports command execution, SOCKS proxying, DNS tunneling, and in-memory kernel module loading. The hackers used public Google Docs to host obfuscated payloads retrieved and executed by their implants, helping the malicious traffic blend in with legitimate Google services.

Symantec published indicators of compromise related to observed Jewelbug activity, as well as a more detailed technical report describing the threat actor's tooling and tradecraft, their financial operation, and the infrastructure used in attacks.

Once attackers have valid credentials, only 37% of their actions are blocked. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free