Protect.Computer
NEWS

Jewelbug APT Breaches Government Webmail Alongside Crypto Fraud

· 1 min read · Got hacked Digital scams
Jewelbug APT Breaches Government Webmail Alongside Crypto Fraud

A China-linked threat actor tracked as Jewelbug — also known as Earth Alux and REF7707 — has been running espionage operations against governments while simultaneously operating an industrial-scale cryptocurrency fraud business from the same infrastructure, according to new research from Symantec.

In one documented operation, the group compromised a shared webmail platform operated by a state telecommunications provider in the Middle East, gaining write access to a common template that then ran malicious JavaScript across all 15 government tenants using that system. Every time a user on one of nine government domains logged in, the script fired and sent their webmail cookies to the attacker’s command-and-control server. High-value targets received a fake Adobe Flash update prompt that installed the Antino backdoor and a malicious browser extension — named “PDF Viewer” — capable of stealing cookies, intercepting traffic, and remotely controlling browser functions. Symantec obtained access to Jewelbug’s C2 management platform and found over one million implant check-in rows, more than 580,000 stolen browser cookies, thousands of captured credentials, and over 2,300 exfiltrated email bodies. The same infrastructure served a parallel criminal operation that deployed AI-generated fake pages impersonating crypto exchanges OKX and Binance — backed by click-fraud bots to manipulate search rankings — along with lures for sports betting and private detective scams.

The dual nature of the operation is unusual: the espionage campaign and the cryptocurrency fraud shared the same C2 dashboard, suggesting Jewelbug may operate partly as a hack-for-hire group that monetizes access beyond its state-directed objectives. Government and military organizations across the Middle East, Southeast Asia, and South Asia were targeted in the espionage track.

Sources

Related reading