China-Linked Hacking Group Compromises Government Email Systems and Crypto Wallets
A China-linked mercenary hacking group called Jewelbug has been running government espionage operations across the Middle East, South Asia, and Southeast Asia, as well as defrauding Chinese-speaking cryptocurrency users from a single dashboard.
The group, also known as Earth Alux, REF7707, and CL-STA-0049, has been active since at least the second quarter of 2023. In August 2026, Broadcom's Symantec Threat Hunter Team published its findings after a months-long investigation.
Jewelbug compromised an entire national government's email system with a single move by breaching the shared web-hosting platform run by one Middle Eastern country's state-owned telecommunications provider. The group planted a malicious script that deployed across more than 15 government webmail tenants at once, allowing them to collect sensitive information.
The script ran automatically on the login page and on every mailbox view, opening a WebSocket connection to Jewelbug's command-and-control server and reporting sessions. It also harvested browser cookies and cross-referenced email addresses against a list of targeted domains.