Researchers have uncovered Jewelbug, an advanced persistent threat group operating out of China. This group is engaged in both international cyber espionage and cryptocurrency theft, a dual operation managed through a single command-and-control panel. Symantec's recent findings reveal that Jewelbug seamlessly toggles between these activities, targeting a variety of sectors including government, military, and telecommunications in Asia and the Middle East.
Jewelbug's operations are supported by three custom malware implants: a Windows backdoor called Antino and a Linux backdoor known as ClientKing, both commonly used in espionage attacks. The standout tool in their arsenal is a browser extension misleadingly named 'PDF Viewer.' This extension, instead of reading PDFs, requests extensive permissions to steal cookies, session tokens, browsing history, and more. It can also execute JavaScript on any webpage, allowing attackers to manipulate victim interactions as if they were physically present.
The group utilizes AI to create a vast network of phishing websites, covering themes like cryptocurrency and sports betting. These are managed by 44 content management servers and optimized for higher search engine rankings using click-fraud bots. Jewelbug's operations are coordinated through a platform called XG-Web, which features role-based access controls to manage infections and stolen data effectively.
Their most notable operation involved infiltrating a Middle Eastern government's web hosting platform, allowing them to plant scripts that compromised government email accounts. Jewelbug's campaigns have also targeted military and industrial sectors in Southeast Asia and the United States, accumulating a vast trove of stolen data including browser cookies, email bodies, and login credentials.
While there is no direct evidence linking Jewelbug to the Chinese government, the group's activities and targets strongly suggest a connection. The use of third-party contractors for cyber operations is a growing trend among nation-states, particularly in China, posing challenges for cybersecurity professionals in attributing attacks and understanding the full scope of these threats.


