Jewelbug's Dual Ops: China-Linked Group Spies on Govs, Swipes Crypto
A Chinese-based mercenary APT group known as Jewelbug has been conducting international cyber espionage and cryptocurrency theft, according to a recent report by Symantec.
The group operates a single custom command-and-control (C2) panel for both operations, utilizing three primary malware implants: Antino, ClientKing, and the browser extension 'PDF Viewer.'
Jewelbug's PDF Viewer is particularly versatile, capable of stealing cookies, session tokens, and screenshots, injecting JavaScript, and potentially replacing cryptocurrency addresses during transactions.
The group has compromised government, military, and telecommunications organizations in Asia and the Middle East, as well as a major U.S. industrial manufacturer.
Symantec researchers discovered hundreds of thousands of stolen cookies and thousands of login credentials, indicating a significant number of victims.