HomeSecurityJewelbug company steals government emails and sets up cryptocurrency scams

Jewelbug operation steals government emails and runs cryptocurrency scams

How can a group combine cyberespionage against government networks with a parallel cryptocurrency fraud operation? The Jewelbug operation provides a disturbing example, as researchers identified shared infrastructure, stolen data, and large-scale campaigns.

Jewelbug operation on compromised government webmail

According to a report by BleepingComputer, the Jewelbug group, also known as Earth Alux or REF7707, is targeting government and military organizations in the Middle East and Asia. The activity is attributed to a group based in China, but the identities of specific operators have not been publicly confirmed.

See also: Chinese Jewelbug was on the network of a Russian IT provider

The Jewelbug operation inside government webmail

In a recent campaign, the attackers compromised accounts belonging to 15 government organizations. Instead of infecting individual users, they obtained registration rights to a shared hosting platform and added a malicious script to the common webmail template.

The script ran on both the login page and in each mailbox view. It opened a WebSocket connection to a control server, extracted webmail cookies, and checked whether the email address belonged to a government domain. This technique allowed the Jewelbug operation to quickly isolate the most useful targets.

Malicious script and cookie theft from government webmail

The scale of the data is particularly large. The researchers recorded approximately 1.1 million geolocation events from 4,300 different IP addresses, while the database contained more than a million communication records of the malicious implants, over 580,000 cookies and thousands of credentials. More than 2,300 email bodies were also recorded.

The geographic scope confirms that this was not an isolated breach. In one Southeast Asian country, approximately 87,200 connections to government and military networks were recorded, while in a Middle Eastern country, connections reached 53,100 and included Starlink addresses. In a second Asian country, approximately 15,000 connections related to ministries were detected.

From the fake update to Antino

When an account of interest was detected, the victim would see a fake Adobe Flash update notification. The installation delivered the Antino, which was used to deploy additional payloads on Windows systems. Researchers linked the infections to Jewelbug's infrastructure.

The same infrastructure also featured XG-Web, a remote access and data theft framework, as well as a malicious extension called “PDF Viewer.” The extension targeted Chrome and Firefox, and was able to steal cookies and credentials, intercept traffic, and inject JavaScript into the browser.

Fake Windows update delivered by Antino

Meanwhile, the ClientKing tool, written in Rust, targeted Linux servers, ARM64 devices, and ASUS routers. It supported command execution, SOCKS proxying, DNS tunneling, and loading kernel modules into memory. The use of public Google Docs for obfuscated payloads made the malicious traffic look more like legitimate communication.

The second aspect: cryptocurrency fraud

The same control console also coordinated a financially motivated activity. Jewelbug created thousands of pages of AI-generated text, published them on dozens of content management servers, and used similar websites that mimicked exchanges like OKX and Binance.

Bots manipulated search engine rankings so that fake pages would attract visitors. The research also describes lures around sports betting, pirated live streaming services and purported private investigators. The coexistence of espionage and fraud shows that the Jewelbug operation is not limited to a single purpose.

The financial side appears to operate as a separate revenue stream, but uses the same operational organization. Symantec attributes this activity with high confidence to a Chinese company advertising SEO services, without publicly naming the company or documenting the identities of individual operators.

See also: Chinese UAT-8302 hackers target governments with custom malware

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Roundcube vulnerabilities: Chinese hackers attack universities

Symantec has published indicators of compromise and technical information about the campaign. Organizations using shared webmail templates should check for unauthorized changes, revoke active sessions and cookies, enforce multi-factor authentication, and look for unusual WebSocket connections. Particular attention should be paid to fake updates and browser extensions outside of official stores.

Monitoring shouldn't be limited to servers. It's worth checking administrator accounts, shared template files, and recently installed extensions, while security teams can look for requests to unknown Google Docs and unusual extraction of content from mailboxes.

The key takeaway is that the Jewelbug operation leverages the same infrastructure for different forms of profit and access. For defenders, this means that an indication of cookie theft or a suspicious change in a webmail template could be part of a much broader campaign.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS