Jewelbug: China-Based Group Runs Espionage and Crypto Fraud Operations Side by Side
A China-based hackers-for-hire group known as Jewelbug has been running parallel operations, including espionage against governments and militaries across Asia and the Middle East, as well as a for-profit cryptocurrency fraud business.
The group's control panel, XG-Web, is a browser-centric remote-access and information-stealing framework that allows operators to turn a victim's browser into a full remote-control channel.
Jewelbug's main implant is the Antino backdoor, which uses the Microsoft Graph API as its command-and-control channel, hiding its traffic inside legitimate Microsoft cloud services.
The group also operates a malicious Chrome and Firefox extension called 'PDF Viewer', which harvests credentials, exfiltrates cookies, and captures history, bookmarks, screenshots, and clipboard data.