Jewelbug's Web of Espionage: China-Linked Threat Actor Targets Governments, Militaries
China-linked threat actor Jewelbug has been carrying out massive cyber espionage operations targeting governments and militaries, while simultaneously engaging in cryptocurrency fraud. The group's browser-centric remote-access and information-stealing framework, XG-Web, allows for parallel operations from a single control panel.
Jewelbug is assessed to be a China-based hackers-for-hire group that runs parallel operations, including espionage against governments and militaries across the Middle East, Southeast Asia, and South Asia. The group has developed five generations of command-and-control (C&C) code and a family of implants spanning browsers, Windows endpoints, Linux servers, and network devices.
The threat actor's financial arm is operated as a registered Chinese company that advertises a commercial search engine optimization (SEO) service on Telegram. However, it is assessed to be a front for an SEO poisoning scheme involving AI-generated fake pages impersonating OKX and Binance, more than 40 content management servers, and click fraud bots.