Jewelbug Exposed: China-Based Hacker-For-Hire Group Runs Parallel Espionage and Crypto Fraud Campaigns
A China-based hacker-for-hire group known as Jewelbug has been exposed for running parallel espionage and cryptocurrency fraud campaigns from a single command-and-control panel. According to research by Broadcom's Symantec Threat Hunter Team, Jewelbug appears equally comfortable stealing state secrets as draining crypto wallets.
The group's dual cyber operations involve government espionage activities, where it compromised government, military, and telecommunications targets across Asia and the Middle East. In one notable operation, Jewelbug targeted a Middle Eastern government by breaching a shared web hosting platform run by the country's state-owned telecom and network services provider.
Jewelbug also runs a cryptocurrency fraud scheme that relies heavily on automation and artificial intelligence to build convincing fake trading sites at scale. The group uses AI tools to generate thousands of phishing pages themed around cryptocurrency, sports betting, and other topics, all managed through a fleet of 44 content management servers.
The researchers found that Jewelbug's crypto operation involves impersonation of Binance and OKX via lookalike domains, with hundreds of fake exchange sites created to trick users into handing over credentials or funds. The group has also compromised more than 580,000 browser cookie sets and exfiltrated over 2,300 email bodies tied to its operations.