Chinese Hacker Group Jewelbug Combines Espionage with Crypto Fraud
A Chinese hacker-for-hire group called Jewelbug has been running dual-purpose operations involving government espionage and cryptocurrency fraud. Symantec's Threat Hunter Team published findings revealing Jewelbug's playbook, which combines state-level surveillance tools with fake crypto exchange websites designed to drain wallets.
The group, active since mid-2023, primarily targets government entities in the Middle East, Southeast Asia, South Asia, and Taiwan through its espionage operations. One campaign involved planting a malicious script across more than 15 government webmail tenants on a shared hosting platform.
Jewelbug's crypto fraud arm relies on a malicious browser extension that harvests credentials and includes a clipboard module capable of swapping cryptocurrency wallet addresses without the user noticing. The group has registered hundreds of lookalike domains and created thousands of fake downloads for crypto exchanges, primarily targeting Chinese-speaking victims.