Security researchers analyzed Jewelbug, a China-based hackers-for-hire group running espionage and crypto fraud campaigns from a single control panel across the Middle East and Asia. The investigation found over 1 million implant check-ins and 580,000 stolen browser cookies in less than three months, along with numerous domains, subdomains, and IPs tied to the operation. #Jewelbug #SocGholish #Cloudflare #Azure #CloudFront
Keypoints
- Researchers attributed espionage and crypto fraud activity to Jewelbug, a China-based hackers-for-hire group.
- Both campaigns were managed through a single control panel and targeted victims across the Middle East and Asia.
- The victim database recorded more than 1 million implant check-ins and over 580,000 stolen browser cookies in under three months.
- Researchers identified 27 network IoCs initially, later expanding the set to 32 network IoCs for deeper DNS analysis.
- Several subdomains were linked to malicious infrastructure, including fake browser-update lures and brand-abusing or typosquatted domains.
- DNS and WHOIS analysis uncovered long-lived infrastructure, historical domain/IP resolutions, and thousands of related email-connected domains.
- One related domain, q-vpn[.]com, was confirmed to have been weaponized to distribute malware since January 2025.
MITRE Techniques
- [T1036 ] Masquerading – The group used lookalike and misleading domain names to imitate legitimate services or brands (‘could be mimicking the Microsoft Azure domain’, ‘could be abusing the Chrome brand’, ‘could be imitating a nameserver’).
- [T1583 ] Acquire Infrastructure – The attackers used multiple domains, subdomains, IPs, and cloud-hosted resources to support their campaigns (‘the group’s victim database recorded 1 million+ implant check-ins’, ‘single control panel’, ’27 network IoCs’).
- [T1071 ] Application Layer Protocol – The infrastructure included domains and cloud services used for web-based malware delivery and communications (‘fake browser update lure hosted on free Cloudflare pages’, ‘malware distributor’).
- [T1204 ] User Execution – A fake browser update lure was used to entice victims into interacting with malicious content (‘SocGholish-style fake browser update lure’).
- [T1566 ] Phishing – The fake browser update lure functioned as a social engineering delivery method to trick users (‘fake browser update lure’).
- [T1480 ] Execution Guardrails – The infrastructure analysis showed controlled, staged hosting and possible operator-specific tradecraft across clusters (‘shared operator tradecraft’, ‘staging infrastructure’).
Indicators of Compromise
- [Subdomains] malicious or suspicious infrastructure – browser-update[.]pages[.]dev, eastus2[.]wac-azure[.]com, and other 8 subdomains
- [Domains] registered and historically resolved domains – wizkidblogger[.]com, mailbycloud[.]com, and other 8 domains
- [IP addresses] attacker infrastructure and historical resolutions – 43[.]246[.]208[.]179, 43[.]246[.]208[.]236, and other 10 IPs
- [Email addresses] historical WHOIS contacts used to expand related infrastructure – 18 unique email addresses, 9 public email addresses
- [Email-connected domains] domains linked through historical WHOIS email records – q-vpn[.]com, huayangtg[.]com, and 5,329 more domains
- [String-connected domains] domains linked by shared string artifacts – 74 domains, including 3 confirmed malicious domains
- [Victim-connected IP addresses] IPs seen communicating with Jewelbug infrastructure – 670 distinct victim IPs across 52 ASNs