China-Based Hacker Group Exposed for Crypto Scam and State-Sponsored Espionage
Jewelbug is a China-based hacker-for-hire group conducting cyber espionage and cryptocurrency fraud. According to new research from Broadcom's Symantec Threat Hunter Team, Jewelbug operates as a mercenary outfit that appears equally comfortable stealing state secrets as it is draining crypto wallets.
The group runs parallel espionage and cryptocurrency fraud campaigns from a single command-and-control panel. In its espionage activities, Jewelbug compromised government, military, and telecommunications organizations across Asia and the Middle East, including a major US industrial and aerospace manufacturer. The attackers planted a script on webmail platforms to steal login cookies and serve fake Adobe Flash update prompts hiding malware.
Jewelbug's cryptocurrency scheme relies heavily on automation and artificial intelligence to build convincing fake trading sites at scale. The group uses AI tools to generate thousands of phishing pages themed around cryptocurrency, sports betting, and other topics, all managed through a fleet of 44 content management servers.
The group impersonates Binance and OKX by registering hundreds of lookalike domains built to mimic these exchanges. This effort aims to trick users into handing over credentials or funds through what appear to be Binance fake exchange sites.