The Chinese hacking group Jewelbug operates government espionage and a large-scale cryptocurrency fraud business in parallel.
In a recent operation against a country in the Middle East, the group, also known as Earth Alux or REF7707, gained write access to a shared webmail installation used by several government ministries and agencies. This was made possible by the prior compromise of a shared web hosting platform operated by the state telecommunications provider. Via a single injected script tag in the shared template, the attackers ensured that whenever a user logged in on one of the nine affected government domains, a WebSocket connection was established to their control server. Symantec describes it as follows:
“A single campaign spanned more than 15 government webmail tenants, with the trigger taking effect both on the login page and with every mailbox view.”
Symantec
After execution, the script exfiltrated webmail cookies and retrieved the user’s email address to check whether it belonged to a targeted government domain. Particularly high-value targets subsequently received a fake prompt to update Adobe Flash, through which the actual malware was installed under Windows, including the Antino backdoor as well as additional browser tools. One of the downloaded programs is a malicious extension for Chrome and Firefox disguised as a PDF Viewer, which steals cookies and credentials, intercepts traffic, injects JavaScript, and makes browser functions remotely accessible.
More than one million logged events in webmail
Symantec managed to trace the Antino infections back to Jewelbug’s infrastructure, gaining insight into the group’s management platform, database, server logs, source code, and internal operator files. The researchers explained: “Jewelbug’s victim database contains more than one million implant check-in entries, more than 580,000 stolen browser cookies, several thousand captured credentials, and more than 2,300 exfiltrated email contents.”
In terms of actual espionage activity, Jewelbug targeted government and military organizations in the Middle East as well as in Southeast and South Asia: The server logs recorded around 1.1 million geolocation events across approximately 4,300 distinct source IP addresses, including around 87,200 connections from a Southeast Asian country targeting state telecommunications and military networks there, as well as around 53,100 connections from a country in the Middle East, including addresses connected via Starlink in the respective capital.
AI-generated fake articles drive crypto fraud
According to Symantec, the financially motivated side of the group relies on an automated attack pipeline that systematically gathers search terms, uses AI to generate thousands of fake download pages, and publishes them across a fleet of 44 content management servers and hundreds of fake domains mimicking well-known crypto exchanges such as OKX and Binance. Using click bots, the attackers additionally manipulate the search engine rankings of these fraudulent pages. In addition to fake crypto exchanges, the group also uses lures from sports betting, illegal streaming portals, and scams involving fake detective services. Symantec attributes these financially motivated activities with high confidence to a Chinese company that officially offers SEO services.
Additionally, Jewelbug deploys an implant written in the Rust programming language called ClientKing, which specifically targets Linux servers, ARM64 devices, and Asus routers, supporting command execution, SOCKS proxying, DNS tunneling, and in-memory loading of kernel modules. To obfuscate malicious traffic, the attackers also abused publicly accessible Google Docs documents to host obfuscated malicious code retrieved and executed by the implants.
(Editorial Team)