The Jewelbug hacking group is conducting cyberespionage campaigns against government and military organizations while simultaneously operating large-scale cryptocurrency scams.
The threat actors have targeted agencies and critical infrastructure organizations in the defence, telecommunications, education, and aviation sectors. Their cryptocurrency activity suggests Jewelbug may also operate as a financially motivated, hack-for-hire or cybercrime group.
In a recent campaign targeting a Middle Eastern country, Jewelbug—also known as Earth Alux and REF7707—compromised webmail accounts belonging to 15 government tenants.
Symantec researchers found that the group’s espionage and cryptocurrency fraud operations were managed through the same command-and-control platform.
The China-based hackers gained write access to a shared webmail installation and modified a common template to inject malicious JavaScript. The code executed on login pages and mailbox views used by the 15 targeted government tenants.
.jpg)
Source: Symantec
After execution, the script opened a WebSocket connection to the attackers’ command-and-control (C2) server. It then stole the webmail cookie, extracted the user’s email address, and checked whether the account belonged to a targeted government domain.
High-value victims were shown a fake Adobe Flash update prompt. If they interacted with it, the attackers deployed the Antino backdoor and additional browser-focused tools on Windows systems.
Jewelbug also uses the XG-Web remote-access and data-theft framework to manage campaigns, monitor victims, and organize stolen information.

Source: Symantec
According to Symantec, Jewelbug delivers Antino through malicious HTA files and fake Adobe Flash or Adobe software installers. These files are used to deploy additional malware and surveillance tools.
One payload is a malicious Chrome and Firefox extension called PDF Viewer. Despite its harmless-sounding name, the extension can steal cookies and credentials, intercept browser traffic, inject JavaScript, and provide remote access to browser functions.

Source: Symantec
Symantec linked the Antino infections to Jewelbug infrastructure and obtained visibility into the group’s C2 management platform, databases, server logs, source code, and operator files.
The evidence revealed both a large-scale cyberespionage operation and what researchers described as an “industrial-scale cryptocurrency fraud business.”
“Jewelbug’s victim database contains over 1 million implant check-in lines, over 580,000 stolen browser cookies, thousands of captured credentials, and over 2,300 leaked email texts,” Symantec researchers said.
The espionage campaign targeted government and military organizations across the Middle East, Southeast Asia, and South Asia.
“Runtime server logs record approximately 1.1 million geolocation events for approximately 4,300 distinct source IP addresses, including approximately 87,200 connections from countries in Southeast Asia (covering national communications and military networks), approximately 53,100 connections from countries in the Middle East (across national carrier coverage, including Starlink connectivity addresses in capital cities), and approximately 1.1 million connections from secondary countries in Southeast Asia 15,000 (including infrastructure for government ministries).” Symantec says.
Researchers said the attackers obtained write access to webmail systems used by multiple government departments after compromising a shared hosting platform operated by the country’s telecommunications provider and Department of State Services.
By adding a single script tag to the shared webmail template, Jewelbug caused a JavaScript payload to connect to its C2 server whenever a user from one of nine government domains logged in.
“The single campaign spanned over 15 government webmail tenants, with hooks launched on login pages and all mailbox views,” Symantec said.
Jewelbug’s cryptocurrency fraud operations use AI-generated articles to attract visitors to fake cryptocurrency exchange websites. The group also relies on click-fraud bots to manipulate search engine rankings and increase traffic to scam pages.

Source: Symantec
According to the researchers, Jewelbug uses an automated attack pipeline that collects keywords, generates thousands of fake download pages with artificial intelligence, and publishes them across a content management network of 44 servers and hundreds of related domains. Many of the sites impersonate major cryptocurrency exchanges, including OKX and Binance.
Click bots are then used to artificially boost search rankings and promote the fraudulent pages. The same infrastructure also advertises sports betting websites, pirated livestream services, and private investigator scams.
Symantec believes Jewelbug’s financially motivated activity may be operated by a Chinese company that promotes search engine optimization services.
Jewelbug also deploys a Rust-based implant called ClientKing. The malware targets Linux servers, ARM64 devices, and ASUS routers, supporting command execution, SOCKS proxying, DNS tunneling, and in-memory kernel module loading.
The attackers used publicly available Google Docs to host obfuscated payloads. ClientKing downloaded and executed these payloads, allowing malicious traffic to blend with legitimate Google services.
Symantec has published indicators of compromise associated with Jewelbug activity. The detailed technical report describes the group’s malware, attack techniques, financial operations, and supporting infrastructure.
Prevention scores do not always show what happens after an attacker gains initial access. When criminals use valid credentials, security defenses can weaken significantly.
Blue Report 2026 evaluates defensive technologies using 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com




