China's Jewelbug APT Group Caught Running Parallel Espionage and Crypto Fraud Operations
The China-based Jewelbug APT group has been exposed for running government espionage and cryptocurrency fraud in parallel, operating from a shared infrastructure and control panel. The group targeted government ministries across the Middle East, Southeast Asia, and South Asia, focusing on government communications and hosting providers.
Jewelbug compromised a web-hosting platform run by a state telecommunications provider, gaining write access and planting a script that stole login cookies and served fake Adobe Flash update prompts to compromise victims' sessions. The group's XG-Web panel allows operators to manage campaigns, collect stolen data, and issue commands across compromised browsers and systems.
The Antino backdoor is delivered as a fake Adobe Flash or installer, using the Microsoft Graph API as its command-and-control channel. The 'PDF Viewer' extension requests sweeping permissions and can execute shell commands on the host through a disguised helper component. The group's commercial arm is tied to a registered company in Hunan Province, China, advertising an SEO service.