Jewelbug Targets the Middle East and Asia via Cyber Espionage and Crypto Fraud Campaigns

Jewelbug Targets the Middle East and Asia via Cyber Espionage and Crypto Fraud Campaigns
Security researchers analyzed Jewelbug, a China-based hackers-for-hire group running espionage and crypto fraud campaigns from a single control panel across the Middle East and Asia. The investigation found over 1 million implant check-ins and 580,000 stolen browser cookies in less than three months, along with numerous domains, subdomains, and IPs tied to the operation. #Jewelbug #SocGholish #Cloudflare #Azure #CloudFront

Keypoints

  • Researchers attributed espionage and crypto fraud activity to Jewelbug, a China-based hackers-for-hire group.
  • Both campaigns were managed through a single control panel and targeted victims across the Middle East and Asia.
  • The victim database recorded more than 1 million implant check-ins and over 580,000 stolen browser cookies in under three months.
  • Researchers identified 27 network IoCs initially, later expanding the set to 32 network IoCs for deeper DNS analysis.
  • Several subdomains were linked to malicious infrastructure, including fake browser-update lures and brand-abusing or typosquatted domains.
  • DNS and WHOIS analysis uncovered long-lived infrastructure, historical domain/IP resolutions, and thousands of related email-connected domains.
  • One related domain, q-vpn[.]com, was confirmed to have been weaponized to distribute malware since January 2025.

MITRE Techniques

  • [T1036 ] Masquerading – The group used lookalike and misleading domain names to imitate legitimate services or brands (‘could be mimicking the Microsoft Azure domain’, ‘could be abusing the Chrome brand’, ‘could be imitating a nameserver’).
  • [T1583 ] Acquire Infrastructure – The attackers used multiple domains, subdomains, IPs, and cloud-hosted resources to support their campaigns (‘the group’s victim database recorded 1 million+ implant check-ins’, ‘single control panel’, ’27 network IoCs’).
  • [T1071 ] Application Layer Protocol – The infrastructure included domains and cloud services used for web-based malware delivery and communications (‘fake browser update lure hosted on free Cloudflare pages’, ‘malware distributor’).
  • [T1204 ] User Execution – A fake browser update lure was used to entice victims into interacting with malicious content (‘SocGholish-style fake browser update lure’).
  • [T1566 ] Phishing – The fake browser update lure functioned as a social engineering delivery method to trick users (‘fake browser update lure’).
  • [T1480 ] Execution Guardrails – The infrastructure analysis showed controlled, staged hosting and possible operator-specific tradecraft across clusters (‘shared operator tradecraft’, ‘staging infrastructure’).

Indicators of Compromise

  • [Subdomains] malicious or suspicious infrastructure – browser-update[.]pages[.]dev, eastus2[.]wac-azure[.]com, and other 8 subdomains
  • [Domains] registered and historically resolved domains – wizkidblogger[.]com, mailbycloud[.]com, and other 8 domains
  • [IP addresses] attacker infrastructure and historical resolutions – 43[.]246[.]208[.]179, 43[.]246[.]208[.]236, and other 10 IPs
  • [Email addresses] historical WHOIS contacts used to expand related infrastructure – 18 unique email addresses, 9 public email addresses
  • [Email-connected domains] domains linked through historical WHOIS email records – q-vpn[.]com, huayangtg[.]com, and 5,329 more domains
  • [String-connected domains] domains linked by shared string artifacts – 74 domains, including 3 confirmed malicious domains
  • [Victim-connected IP addresses] IPs seen communicating with Jewelbug infrastructure – 670 distinct victim IPs across 52 ASNs


Read more: https://circleid.com/posts/jewelbug-targets-the-middle-east-and-asia-via-cyber-espionage-and-crypto-fraud-campaigns