Researchers Link 'Jewelbug' Chinese APT to Hack
Security researchers from Broadcomâs Threat Hunter Team have revealed that Jewelbug, a threat group associated with Chinese-sponsored cyber espionage operations, may be a hacker-for-hire group that also runs profitable crypto fraud campaigns.
In a new report published on August 13, the threat intelligence team â which brought together experts from Symantec and Carbon Black â shed new light on the advanced persistent threat (APT) group, also known as Ink Dragon, Earth Alux, REF770 and CL-STA-0049.
The researchers revealed that Jewelbug uses the same infrastructure to conduct espionage against governments and militaries across the Middle East, Southeast Asia and South Asia as well as a financially motivated operation targeting Chinese-speaking cryptocurrency users through fake exchange-download portals.
âThe two are not separate ventures that happen to share a name: our investigation revealed they are run by the same small team, on shared infrastructure, from one control panel,â the Broadcom report noted.
At least one of the operators, likely running what Broadcom described as âthe commercial arm of the business,â identified as âople500â in the groupâs control panel, has been identified as using the âpaopaodadaâ (âbubble bossâ) persona.
This individual has been advertised on Telegram as the contact for a âwebsite ranking rentalâ service. Broadcom associated the individual âwith high confidenceâ to a company, described as an SEO business, registered in Changsha, the capital of the Hunan province.
The Threat Hunter Team has identified the name of the sole legal representative of this company and assessed that that person supplies access, infrastructure and delivery to the espionage operation rather than being part of the team of operators.
Cyber Espionage Targets
Jewelbug's cyber espionage operations had already been reported by various threat intelligence teams, including Trend Micro's TrendAI, Palo Alto Networks' Unit 42 and Check Point Research.
Researchers found the actor typically gained access through vulnerable IIS and SharePoint servers before deploying web shells and a sophisticated backdoor tracked as VARGEIT, Squidoor or FinalDraft.
The malware supported multiple covert command-and-control (C2) methods, including Microsoft Graph/Outlook APIs, DNS tunnelling and ICMP tunnelling.
After a months-long investigation into some of the threat groupâs operations, Broadcom researchers found it has targeted several government organizations across the Middle East and Southeast Asia, with more than 90 police and government email addresses in South Asia.
They also found a victim database which recorded more than one million implant check-ins and over 580,000 stolen browser cookies in less than three months of active operations.
One set of implants was configured to utilize the internal proxy of a major US aerospace and industrial manufacturer.
In its largest operation, a single planted script placed a watering-hole on more than 15 government webmail tenants in a Middle Eastern country at once.
Crypto Fraud Targets
Meanwhile, some of Jewelbug's infrastructure was used to run a cryptocurrency fraud business on the side.
The Broadcom researchers said the group operated a financially motivated campaign targeting Chinese-speaking cryptocurrency users through fake exchange-download websites, while decoy documents themed around Taiwanese government organizations suggested it also had an interest in Taiwan.
The report added that the common thread across the group's espionage targets was government communications systems and the service providers that host them, potentially providing long-term access to official correspondence.
Jewelbugâs Common Infrastructure for Espionage and Fraud
At the center of both the espionage and cryptocurrency fraud operations was XG-Web, a browser-based C2 platform that acted as the group's central management console.
According to the Broadcom report, the same XG-Web infrastructure was used to administer victims from both campaigns, with implants, stolen data and operator activity all feeding into a shared backend database.
One of the primary tools connected to this infrastructure was Antino, the group's Windows backdoor.
Antino communicated with operators through the Microsoft Graph API, allowing C2 traffic to blend in with legitimate Microsoft cloud services.
The Broadcom report said the malware was used across multiple Jewelbug campaigns and was deployed through fake software installers and themed lures.
The group also operated a malicious Chrome and Firefox extension called âPDF Viewer,â which was paired with a helper program disguised as a Microsoft Edge component. The combination gave operators extensive access to victims' browsers, enabling them to steal cookies, credentials and browsing data, while also providing a command shell on the compromised host through a native messaging component.
Alongside Antino, Jewelbug used a Linux and router implant known as ClientKing, which supported multiple C2 methods, including DNS tunnelling and provided remote shell access and pivoting capabilities.
The researchers noted that ClientKing infrastructure overlapped with the group's wider XG-Web ecosystem, further linking the espionage and fraud operations.
Finally, the group also abused Google Docs for payload delivery and C2. When operators launched a campaign, the backend created public Google documents containing obfuscated payloads, which implants would retrieve and execute. By leveraging Google's infrastructure, the group was able to disguise malicious activity as legitimate traffic and reduce the likelihood of detection.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content â general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached â you'll always get the same 5 for this article.