Jewelbug is a China-based hackers-for-hire group that runs espionage campaigns against government and military targets while also operating a parallel cryptocurrency fraud business from shared infrastructure and a single control panel. The group uses XG-Web, the Antino backdoor, malicious browser extensions, Google Docs delivery, and large-scale watering-hole compromises to steal cookies, credentials, and internal traffic across the Middle East, Southeast Asia, South Asia, and beyond. #Jewelbug #Antino #XGWeb #EarthAlux #REF7707 #CLSTA0049 #CSIS #OKX #Binance
Keypoints
- Jewelbug operates two linked missions: government espionage and a for-profit crypto-fraud business.
- The group is also tracked as Earth Alux, REF7707, and CL-STA-0049, and is assessed to be based in China.
- Both operations are managed through XG-Web, a browser-centric remote-access and credential-stealing platform backed by shared infrastructure.
- The main Windows payload is the Antino backdoor, which is delivered through HTA downloaders and fake software installers.
- A malicious Chrome and Firefox extension disguised as “PDF Viewer” enables credential theft, cookie harvesting, screenshots, clipboard access, and browser hijacking.
- ClientKing is a separate Rust implant for Linux servers, network devices, and routers, with shell access, SOCKS pivoting, and kernel-level capabilities.
- The group’s largest espionage campaign compromised a shared government webmail platform and planted a watering-hole across more than 15 tenants at once.
MITRE Techniques
- [T1189 ] Drive-by Compromise – The group planted a watering-hole on shared government webmail pages to infect visitors who logged in (‘Every government tenant on that platform had a watering-hole planted on it at once.’)
- [T1056.001 ] Keylogging – The browser extension hooked login forms to steal credentials typed by victims (‘The extension harvested credentials by hooking login forms.’)
- [T1539 ] Steal Web Session Cookie – The operators exfiltrated cookies and session tokens from victims’ browsers (‘exfiltrated the victim’s full cookie jar’ and ‘steal new session tokens in near real time’).
- [T1218.005 ] Mshta – Antino was delivered through malicious HTML Application downloaders (‘wave of malicious HTML Application (HTA) downloaders’).
- [T1187 ] Forced Authentication – The implant used a lure and browser interaction to capture authenticated webmail traffic and credentials (‘it captured authenticated traffic to an internal virtualization-management interface’).
- [T1059.003 ] Windows Command Shell – The native-messaging helper ran operator commands through cmd.exe (‘ran operator commands through the Windows command interpreter’).
- [T1056.003 ] Input Capture – The extension captured clipboard contents and other browser data from the victim (‘captured history, bookmarks, screenshots, the clipboard and intercepted traffic’).
- [T1114.001 ] Local Email Collection – The operators exfiltrated mailbox content from government webmail tenants (‘more than 2,300 exfiltrated email bodies’).
- [T1090.001 ] Internal Proxy – Some implants were configured to use an internal corporate proxy to blend into victim networks (‘configured to utilize the internal proxy’).
- [T1105 ] Ingress Tool Transfer – Payloads were fetched from attacker-controlled domains, Google Docs, and remote URLs (‘had implants fetch the documents and execute the payloads’).
- [T1027 ] Obfuscated Files or Information – Payloads were XOR-encoded and otherwise obfuscated to evade detection (‘This was XOR encoded with a random key’).
- [T1071.004 ] DNS – ClientKing supported a custom DNS tunnel for command-and-control (‘including a custom domain-name-system (DNS) tunnel’).
Indicators of Compromise
- [File hashes ] Malicious HTA lures, Antino samples, and related loaders – e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf, 01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a, and other 15+ hashes
- [File names ] Fake installers and DLLs used in the campaign – flashcenter_pp_ax_install_en.exe, Adobeinstall.exe, and related files such as slc.dll and Vb0c44dfslc.dll.wxb
- [Domains ] Attacker-controlled delivery and C2 infrastructure – microsoft-flash[.]com, fonts[.]chrorne[.]com, and other domains such as robot[.]avbliud[.]com and www[.]f1ash[.]org[.]cn
- [IPs ] Runtime geolocation and infrastructure addresses observed in logs – 103[.]87[.]9[.]62, 152[.]42[.]174[.]151, and other IPs including 43[.]246[.]208[.]236 and 47[.]250[.]208[.]35
- [URLs ] Payload delivery and C2 endpoints – hxxps://microsoft-flash[.]com/download/Adobeinstall.exe, hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/hjgzBskgslc.dll.iwq, and hxxp://d2nq35tel3ucuo[.]cloudfront[.]net/LtVGUSsyUTDA.log
- [Registry keys ] Native-messaging registration used by the browser helper – HKCUSOFTWAREGoogleChromeNativeMessagingHostscom.microsoft.runedge
- [Google Docs ] Live operator-controlled documents used for C2 delivery – 13 public Google Documents mapped to active campaigns
Read more: https://www.security.com/threat-intelligence/jewelbug-crypto-fraud-espionage