Skip to content
Back to Guavy Wire
Crypto

Chinese Hacker Group Jewelbug Combines Espionage with Crypto Fraud

Share

A Chinese hacker-for-hire group called Jewelbug has been running dual-purpose operations involving government espionage and cryptocurrency fraud. Symantec's Threat Hunter Team published findings revealing Jewelbug's playbook, which combines state-level surveillance tools with fake crypto exchange websites designed to drain wallets.

The group, active since mid-2023, primarily targets government entities in the Middle East, Southeast Asia, South Asia, and Taiwan through its espionage operations. One campaign involved planting a malicious script across more than 15 government webmail tenants on a shared hosting platform.

Jewelbug's crypto fraud arm relies on a malicious browser extension that harvests credentials and includes a clipboard module capable of swapping cryptocurrency wallet addresses without the user noticing. The group has registered hundreds of lookalike domains and created thousands of fake downloads for crypto exchanges, primarily targeting Chinese-speaking victims.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc