APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Jewelbug is a China-based hackers-for-hire group conducting espionage against government ministries and militaries in the Middle East, Southeast Asia, and South Asia, while simultaneously running cryptocurrency fraud operations. They use a browser-centric remote-access framework called XG-Web to control their operations. Their main implant is the Antino backdoor, supported by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. A major operation compromised over 15 government webmail tenants in a Middle Eastern country via a watering-hole attack, resulting in over one million implant check-ins and 580,000 stolen browser cookies in three months. The operators are linked to a company registered in Hunan Province, China, and also conduct SEO poisoning targeting Chinese-speaking cryptocurrency users.
AI Analysis
Technical Summary
Jewelbug is an advanced persistent threat group based in China that conducts dual operations: espionage targeting government and military entities across multiple Asian regions, and cryptocurrency fraud targeting Chinese-speaking users. Their infrastructure revolves around XG-Web, a browser-based remote access tool. The group employs the Antino backdoor as their primary implant, alongside a malicious browser extension masquerading as 'PDF Viewer' and the ClientKing implant targeting Linux routers. Their largest known campaign involved a watering-hole attack compromising over 15 government webmail tenants in a Middle Eastern country, yielding extensive data collection including over one million implant check-ins and hundreds of thousands of stolen browser cookies within three months. The group's infrastructure and operations are linked to a registered company in Hunan Province, China, and they also engage in commercial SEO poisoning to facilitate cryptocurrency fraud.
Potential Impact
The group’s espionage operations compromise sensitive government and military communications in multiple Asian regions, potentially exposing confidential information. The watering-hole attack on government webmail tenants led to extensive data theft, including over one million implant check-ins and 580,000 stolen browser cookies, which could facilitate further intrusions or credential theft. Concurrently, their cryptocurrency fraud operations target Chinese-speaking users through SEO poisoning, potentially leading to financial losses for victims.
Mitigation Recommendations
No specific patch or remediation is indicated for this threat. Since this is a threat actor employing multiple implants and social engineering techniques, mitigation should focus on detecting and blocking the Antino backdoor, malicious browser extensions like the fake 'PDF Viewer', and the ClientKing implant. Network defenders should monitor for indicators of compromise related to XG-Web framework activity and watering-hole attacks. Given the lack of vendor advisories or patches, organizations should apply general best practices for endpoint security, browser extension controls, and network monitoring tailored to these specific threats. Patch status is not yet confirmed — check vendor advisories and threat intelligence sources for updates.
Indicators of Compromise
- ip: 38.12.1.47
- domain: www.jkskhei.com
- domain: ns1.jkskhei.com
- hash: e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf
- hash: 01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a
- hash: e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34
- hash: f1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8
- hash: e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530
- hash: e7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb
- hash: 09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff
- hash: c11714f9fe2df1ca906585c81498cd77f5ec05b132aab73fa3a71d71d71e42cc
- hash: b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e
- hash: 0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd
- hash: 9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3
- hash: 153d077bcb58e00f5746573cba25f6b0788b809bf7b2a52fca0dc22d3bb5c94e
- hash: 297413a3e49e7353bf484a3eb15ec647de729211059df8fc68678d2378b6f561
- hash: 30f5122cc199b9c2e524503b343a9ee13a6f9773dcbc1df82c8b25ad20bca61d
- hash: 430f12970f8d58f12edccee9019a1aa90fa232c961449bdcc69c8d348a52cf55
- hash: 5ccdf53881f6c758af8d94fe67066af209b4bc0a3cb80b6a4c724fad86eb97ef
- hash: 5edb8d1023b8babf302871b68fa2b26d5ca57633f64951922998e8f1d6c8f7ac
- hash: 6d5fe6b6a34eeb470798b970b70f41a07ccf59b22f49ad9b3dfff7aa3256f3c2
- hash: 97c3a6be1711c5340d8806e4a54f7297f3f763d0aa4240b667f1e4e1f98f2aad
- hash: ac3d453d3c9b0310ebb8a67cef35e2ac954d4acdf70cf497fe43a02c7a510813
- hash: e782a6d4919f194d41e524ebd6df5894197043cf772fcf60455127b246f302c0
- hash: ea893abf20b00d9bfc042a88fbf7b4bd42e68ce07c116d3e3b002e5b4a853877
- hash: ed96e7f1085a50251eb8967ac53777272a617831084f0edad8a769c583a18869
- domain: fonts.tarotfree101.top
- domain: fonts.chrorne.com
- domain: robot.avbliud.com
- domain: microsoft-flash.com
- domain: www.wps-cn.com
- domain: www.f1ash.org.cn
- domain: eastus2.wac-azure.com
- domain: mailbycloud.com
- domain: dns.wizkidblogger.com
- ip: 103.87.9.62
- ip: 43.246.208.236
- ip: 43.246.208.179
- ip: 219.76.254.184
- url: https://microsoft-flash.com/download/flashcenter_pp_ax_install_en.exe
- url: https://www.f1ash.org.cn/flashcenter_pp_ax_install_cn.exe
- url: https://microsoft-flash.com/download/Adobeinstall.exe
- hash: abfa7742e315485a98a5fafd6dbfb68e
- hash: bf681f76dc3b6f497d8c58e705585ae0
- hash: cc648bee6b11ce487565ef67576eb1c6
- hash: 13425b473576aa1e58eee248e7c6a2e216889c58
- hash: e3b2bba523c035177241f6f66168e60fa6abbaaf
- url: https://fonts.chrorne.com/dist/js/12.qgfvjzvs.chunk.xn--js-02t
APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Description
Jewelbug is a China-based hackers-for-hire group conducting espionage against government ministries and militaries in the Middle East, Southeast Asia, and South Asia, while simultaneously running cryptocurrency fraud operations. They use a browser-centric remote-access framework called XG-Web to control their operations. Their main implant is the Antino backdoor, supported by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. A major operation compromised over 15 government webmail tenants in a Middle Eastern country via a watering-hole attack, resulting in over one million implant check-ins and 580,000 stolen browser cookies in three months. The operators are linked to a company registered in Hunan Province, China, and also conduct SEO poisoning targeting Chinese-speaking cryptocurrency users.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Jewelbug is an advanced persistent threat group based in China that conducts dual operations: espionage targeting government and military entities across multiple Asian regions, and cryptocurrency fraud targeting Chinese-speaking users. Their infrastructure revolves around XG-Web, a browser-based remote access tool. The group employs the Antino backdoor as their primary implant, alongside a malicious browser extension masquerading as 'PDF Viewer' and the ClientKing implant targeting Linux routers. Their largest known campaign involved a watering-hole attack compromising over 15 government webmail tenants in a Middle Eastern country, yielding extensive data collection including over one million implant check-ins and hundreds of thousands of stolen browser cookies within three months. The group's infrastructure and operations are linked to a registered company in Hunan Province, China, and they also engage in commercial SEO poisoning to facilitate cryptocurrency fraud.
Potential Impact
The group’s espionage operations compromise sensitive government and military communications in multiple Asian regions, potentially exposing confidential information. The watering-hole attack on government webmail tenants led to extensive data theft, including over one million implant check-ins and 580,000 stolen browser cookies, which could facilitate further intrusions or credential theft. Concurrently, their cryptocurrency fraud operations target Chinese-speaking users through SEO poisoning, potentially leading to financial losses for victims.
Defensive Guidance
No specific patch or remediation is indicated for this threat. Since this is a threat actor employing multiple implants and social engineering techniques, mitigation should focus on detecting and blocking the Antino backdoor, malicious browser extensions like the fake 'PDF Viewer', and the ClientKing implant. Network defenders should monitor for indicators of compromise related to XG-Web framework activity and watering-hole attacks. Given the lack of vendor advisories or patches, organizations should apply general best practices for endpoint security, browser extension controls, and network monitoring tailored to these specific threats. Patch status is not yet confirmed — check vendor advisories and threat intelligence sources for updates.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.security.com/blog-post/jewelbug-crypto-fraud-espionage"]
- Adversary
- REF7707
- Pulse Id
- 6a7daa9c80273555f3d3ccd1
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip38.12.1.47 | — | |
ip103.87.9.62 | — | |
ip43.246.208.236 | — | |
ip43.246.208.179 | — | |
ip219.76.254.184 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainwww.jkskhei.com | — | |
domainns1.jkskhei.com | — | |
domainfonts.tarotfree101.top | — | |
domainfonts.chrorne.com | — | |
domainrobot.avbliud.com | — | |
domainmicrosoft-flash.com | — | |
domainwww.wps-cn.com | — | |
domainwww.f1ash.org.cn | — | |
domaineastus2.wac-azure.com | — | |
domainmailbycloud.com | — | |
domaindns.wizkidblogger.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hashe6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf | — | |
hash01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a | — | |
hashe809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34 | — | |
hashf1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8 | — | |
hashe2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530 | — | |
hashe7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb | — | |
hash09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff | — | |
hashc11714f9fe2df1ca906585c81498cd77f5ec05b132aab73fa3a71d71d71e42cc | — | |
hashb90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e | — | |
hash0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd | — | |
hash9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3 | — | |
hash153d077bcb58e00f5746573cba25f6b0788b809bf7b2a52fca0dc22d3bb5c94e | — | |
hash297413a3e49e7353bf484a3eb15ec647de729211059df8fc68678d2378b6f561 | — | |
hash30f5122cc199b9c2e524503b343a9ee13a6f9773dcbc1df82c8b25ad20bca61d | — | |
hash430f12970f8d58f12edccee9019a1aa90fa232c961449bdcc69c8d348a52cf55 | — | |
hash5ccdf53881f6c758af8d94fe67066af209b4bc0a3cb80b6a4c724fad86eb97ef | — | |
hash5edb8d1023b8babf302871b68fa2b26d5ca57633f64951922998e8f1d6c8f7ac | — | |
hash6d5fe6b6a34eeb470798b970b70f41a07ccf59b22f49ad9b3dfff7aa3256f3c2 | — | |
hash97c3a6be1711c5340d8806e4a54f7297f3f763d0aa4240b667f1e4e1f98f2aad | — | |
hashac3d453d3c9b0310ebb8a67cef35e2ac954d4acdf70cf497fe43a02c7a510813 | — | |
hashe782a6d4919f194d41e524ebd6df5894197043cf772fcf60455127b246f302c0 | — | |
hashea893abf20b00d9bfc042a88fbf7b4bd42e68ce07c116d3e3b002e5b4a853877 | — | |
hashed96e7f1085a50251eb8967ac53777272a617831084f0edad8a769c583a18869 | — | |
hashabfa7742e315485a98a5fafd6dbfb68e | — | |
hashbf681f76dc3b6f497d8c58e705585ae0 | — | |
hashcc648bee6b11ce487565ef67576eb1c6 | — | |
hash13425b473576aa1e58eee248e7c6a2e216889c58 | — | |
hashe3b2bba523c035177241f6f66168e60fa6abbaaf | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://microsoft-flash.com/download/flashcenter_pp_ax_install_en.exe | — | |
urlhttps://www.f1ash.org.cn/flashcenter_pp_ax_install_cn.exe | — | |
urlhttps://microsoft-flash.com/download/Adobeinstall.exe | — | |
urlhttps://fonts.chrorne.com/dist/js/12.qgfvjzvs.chunk.xn--js-02t | — |
Threat ID: 6a7dc5f5bf8831d5393e2c19
Added to database: 08/13/2026, 13:26:13 UTC
Last enriched: 08/13/2026, 17:31:24 UTC
Last updated: 08/13/2026, 17:58:09 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.