Jewelbug has been conducting espionage against governments and militaries while also running cryptocurrency fraud campaigns, with Symantec linking both activities to the same infrastructure. The group used compromised government webmail, fake software prompts, malicious browser tools, and AI-generated scam pages to steal cookies, credentials, and email data. #Jewelbug #EarthAlux #REF7707 #Antino #XGWeb #ClientKing #OKX #Binance
Keypoints
- Jewelbug targeted government and military organizations across multiple regions.
- The group abused shared webmail access to inject a script across 15 government tenants.
- Stolen webmail cookies and credentials were used to identify high-value victims.
- The attackers deployed Antino, PDF Viewer, XG-Web, and ClientKing for spying and data theft.
- Jewelbug also ran AI-driven crypto scams using fake OKX and Binance sites and click-fraud bots.