Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

APT Group Runs Espionage and Crypto Fraud Operations Side by Side

0
Medium
Published: 08/13/2026 (08/13/2026, 11:29:32 UTC)
Source: AlienVault OTX General

Description

Jewelbug is a China-based hackers-for-hire group conducting espionage against government ministries and militaries in the Middle East, Southeast Asia, and South Asia, while simultaneously running cryptocurrency fraud operations. They use a browser-centric remote-access framework called XG-Web to control their operations. Their main implant is the Antino backdoor, supported by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. A major operation compromised over 15 government webmail tenants in a Middle Eastern country via a watering-hole attack, resulting in over one million implant check-ins and 580,000 stolen browser cookies in three months. The operators are linked to a company registered in Hunan Province, China, and also conduct SEO poisoning targeting Chinese-speaking cryptocurrency users.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/13/2026, 17:31:24 UTC

Technical Analysis

Jewelbug is an advanced persistent threat group based in China that conducts dual operations: espionage targeting government and military entities across multiple Asian regions, and cryptocurrency fraud targeting Chinese-speaking users. Their infrastructure revolves around XG-Web, a browser-based remote access tool. The group employs the Antino backdoor as their primary implant, alongside a malicious browser extension masquerading as 'PDF Viewer' and the ClientKing implant targeting Linux routers. Their largest known campaign involved a watering-hole attack compromising over 15 government webmail tenants in a Middle Eastern country, yielding extensive data collection including over one million implant check-ins and hundreds of thousands of stolen browser cookies within three months. The group's infrastructure and operations are linked to a registered company in Hunan Province, China, and they also engage in commercial SEO poisoning to facilitate cryptocurrency fraud.

Potential Impact

The group’s espionage operations compromise sensitive government and military communications in multiple Asian regions, potentially exposing confidential information. The watering-hole attack on government webmail tenants led to extensive data theft, including over one million implant check-ins and 580,000 stolen browser cookies, which could facilitate further intrusions or credential theft. Concurrently, their cryptocurrency fraud operations target Chinese-speaking users through SEO poisoning, potentially leading to financial losses for victims.

Defensive Guidance

No specific patch or remediation is indicated for this threat. Since this is a threat actor employing multiple implants and social engineering techniques, mitigation should focus on detecting and blocking the Antino backdoor, malicious browser extensions like the fake 'PDF Viewer', and the ClientKing implant. Network defenders should monitor for indicators of compromise related to XG-Web framework activity and watering-hole attacks. Given the lack of vendor advisories or patches, organizations should apply general best practices for endpoint security, browser extension controls, and network monitoring tailored to these specific threats. Patch status is not yet confirmed — check vendor advisories and threat intelligence sources for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.security.com/blog-post/jewelbug-crypto-fraud-espionage"]
Adversary
REF7707
Pulse Id
6a7daa9c80273555f3d3ccd1
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip38.12.1.47
ip103.87.9.62
ip43.246.208.236
ip43.246.208.179
ip219.76.254.184

Domain

ValueDescriptionCopy
domainwww.jkskhei.com
domainns1.jkskhei.com
domainfonts.tarotfree101.top
domainfonts.chrorne.com
domainrobot.avbliud.com
domainmicrosoft-flash.com
domainwww.wps-cn.com
domainwww.f1ash.org.cn
domaineastus2.wac-azure.com
domainmailbycloud.com
domaindns.wizkidblogger.com

Hash

ValueDescriptionCopy
hashe6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf
hash01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a
hashe809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34
hashf1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8
hashe2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530
hashe7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb
hash09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff
hashc11714f9fe2df1ca906585c81498cd77f5ec05b132aab73fa3a71d71d71e42cc
hashb90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e
hash0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd
hash9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3
hash153d077bcb58e00f5746573cba25f6b0788b809bf7b2a52fca0dc22d3bb5c94e
hash297413a3e49e7353bf484a3eb15ec647de729211059df8fc68678d2378b6f561
hash30f5122cc199b9c2e524503b343a9ee13a6f9773dcbc1df82c8b25ad20bca61d
hash430f12970f8d58f12edccee9019a1aa90fa232c961449bdcc69c8d348a52cf55
hash5ccdf53881f6c758af8d94fe67066af209b4bc0a3cb80b6a4c724fad86eb97ef
hash5edb8d1023b8babf302871b68fa2b26d5ca57633f64951922998e8f1d6c8f7ac
hash6d5fe6b6a34eeb470798b970b70f41a07ccf59b22f49ad9b3dfff7aa3256f3c2
hash97c3a6be1711c5340d8806e4a54f7297f3f763d0aa4240b667f1e4e1f98f2aad
hashac3d453d3c9b0310ebb8a67cef35e2ac954d4acdf70cf497fe43a02c7a510813
hashe782a6d4919f194d41e524ebd6df5894197043cf772fcf60455127b246f302c0
hashea893abf20b00d9bfc042a88fbf7b4bd42e68ce07c116d3e3b002e5b4a853877
hashed96e7f1085a50251eb8967ac53777272a617831084f0edad8a769c583a18869
hashabfa7742e315485a98a5fafd6dbfb68e
hashbf681f76dc3b6f497d8c58e705585ae0
hashcc648bee6b11ce487565ef67576eb1c6
hash13425b473576aa1e58eee248e7c6a2e216889c58
hashe3b2bba523c035177241f6f66168e60fa6abbaaf

Url

ValueDescriptionCopy
urlhttps://microsoft-flash.com/download/flashcenter_pp_ax_install_en.exe
urlhttps://www.f1ash.org.cn/flashcenter_pp_ax_install_cn.exe
urlhttps://microsoft-flash.com/download/Adobeinstall.exe
urlhttps://fonts.chrorne.com/dist/js/12.qgfvjzvs.chunk.xn--js-02t

Threat ID: 6a7dc5f5bf8831d5393e2c19

Added to database: 08/13/2026, 13:26:13 UTC

Last enriched: 08/13/2026, 17:31:24 UTC

Last updated: 08/13/2026, 17:58:09 UTC

Views: 14

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses