Jewelbug Hacker Group Conducts Parallel Espionage and Crypto Fraud
The Jewelbug hacker group has been carrying out espionage operations and cryptocurrency fraud in parallel. The group, also known as Earth Alux and REF7707, targeted government agencies and organizations in critical sectors such as defense, telecommunications, education, and aviation.
Researchers at Symantec found that the espionage campaign and the cryptocurrency fraud were conducted from the same control panel. Jewelbug gained write access to a shared webmail installation and inserted a malicious script into its common template. The script then ran on login pages and mailbox views across 15 tenants, exfiltrating webmail cookies and retrieving user email addresses.
The threat actor also uses the XG-Web remote-access and data-theft framework for managing campaigns and victim information. Jewelbug delivers Antino through malicious HTA files and fake Adobe Flash/Adobe installers, which then deploy additional payloads. One of these payloads is a browser extension called PDF Viewer that steals cookies and credentials.
Symantec traced Antino infections to Jewelbug's infrastructure and obtained visibility into the group's C2 management platform, database, server logs, source code, and operator files. The data showed that Jewelbug ran a large-scale espionage operation and 'an industrial-scale cryptocurrency fraud business.'