Jewelbug runs espionage and cryptocurrency fraud operations, says Symantec

1 hour ago 20

A Chinese hacker-for-hire group called Jewelbug has been running government espionage campaigns and cryptocurrency fraud operations simultaneously, using the same infrastructure for both. Symantec’s Threat Hunter Team published findings revealing the group’s dual-purpose playbook, which combines state-level surveillance tools with fake crypto exchange websites designed to drain wallets.

The scale is striking. Jewelbug’s centralized command-and-control system, called XG-Web, has tracked over one million implant check-ins across its victim database. The group has stolen more than 580,000 browser cookies and exfiltrated over 2,300 email bodies, all while maintaining a relatively small team with role-based access controls.

A spy agency that moonlights in crypto theft

Jewelbug, which also operates under the aliases Earth Alux and REF7707, has been active since mid-2023. Its espionage operations primarily target government entities in the Middle East, Southeast Asia, South Asia, and Taiwan. One campaign involved planting a malicious script across more than 15 government webmail tenants on a shared hosting platform, a technique known as a waterhole attack.

But spying on diplomats is only half the operation. On the financial crime side, the group has registered hundreds of lookalike domains and created thousands of fake downloads for crypto exchanges. These fraudulent sites are generated with AI and primarily target Chinese-speaking victims.

The crypto fraud arm relies on a malicious browser extension that does more than just harvest credentials. It includes a clipboard module capable of swapping cryptocurrency wallet addresses without the user ever noticing. You copy your intended wallet address, paste it into a transaction, and the extension quietly replaces it with an address controlled by Jewelbug.

The toolkit and the tradecraft

Jewelbug’s technical arsenal includes the Antino Windows backdoor and the aforementioned browser extension, both custom-built. But the group doesn’t rely solely on bespoke malware. It also uses mainstream cybercrime methods like SEO poisoning, where attackers manipulate search engine results to push malicious websites to the top of searches for popular crypto platforms.

The XG-Web command-and-control platform serves as the operational nerve center. It can simultaneously manage espionage implants on government systems and coordinate the fake crypto exchange campaigns. Prior reports dating back to October 2025 had already flagged Jewelbug’s attacks on geopolitical targets, but the crypto fraud dimension adds a new layer.

What this means for crypto security

The clipboard-swapping technique exploits a step that most users consider safe. Copying and pasting a wallet address feels like a security measure, a way to avoid typos. Jewelbug turns that habit into a vulnerability.

The SEO poisoning campaigns compound the problem. The registration of hundreds of lookalike domains suggests this isn’t a targeted operation. It’s a dragnet.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article