Jewelbug: China-Based Hackers-for-Hire Group Runs Parallel Espionage and Crypto Fraud Operations
Jewelbug is a China-based hackers-for-hire group that runs parallel operations in espionage and crypto fraud. The group targets governments and militaries across the Middle East, Southeast Asia, and South Asia for espionage, while running a for-profit cryptocurrency fraud business targeting Chinese-speaking victims.
The group's control panel, XG-Web, is a browser-centric remote-access and information-stealing framework that can reach into a victim's host and internal network. The platform allows operators to administer both missions from a single dashboard, with at least one operator tied to a registered Hunan company.
Jewelbug's main implant is the Antino backdoor, which uses the Microsoft Graph API as its C&C channel, hiding traffic inside legitimate Microsoft cloud services. The group also operates a malicious Chrome and Firefox extension called 'PDF Viewer', paired with a helper disguised as a Microsoft Edge component that gave operators a command shell on the host.
The group's operations have been uncovered by the Symantec Threat Hunter Team, which has produced unprecedented visibility into Jewelbug's activities. The team found that the group's victim database recorded more than one million implant check-ins and over 580,000 stolen browser cookies in less than three months of active operations.