Skip to main content

Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side

0
Medium
Published: 08/13/2026 (08/13/2026, 11:29:32 UTC)
Source: AlienVault OTX General

Description

Jewelbug is a China-based hackers-for-hire group conducting parallel operations: espionage campaigns targeting government ministries and militaries across the Middle East, Southeast Asia, and South Asia, alongside a cryptocurrency fraud business. Both missions operate from a single control panel called XG-Web, a browser-centric remote-access framework. The group's main implant is the Antino backdoor, complemented by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. Their largest operation compromised over 15 government webmail tenants in a Middle Eastern country through a single watering-hole attack. The victim database recorded over one million implant check-ins and 580,000 stolen browser cookies within three months. Operators are linked to a registered Hunan Province company, with infrastructure supporting both espionage and commercial SEO poisoning operations targeting Chinese-speaking cryptocurrency users.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/19/2026, 22:02:33 UTC

Technical Analysis

Jewelbug is a hackers-for-hire APT group based in China that conducts parallel operations: espionage campaigns targeting government ministries and militaries across multiple Asian regions, and cryptocurrency fraud targeting Chinese-speaking users. Both operations are managed through a single control panel named XG-Web, a browser-centric remote-access framework. Their main implant is the Antino backdoor, supplemented by a malicious browser extension ('PDF Viewer') and the ClientKing implant targeting Linux routers. The group’s largest known campaign compromised over 15 government webmail tenants in a Middle Eastern country through a watering-hole attack, generating over one million implant check-ins and stealing 580,000 browser cookies within three months. The operators are linked to a company registered in Hunan Province, China, and their infrastructure supports both espionage and commercial SEO poisoning operations.

Potential Impact

The group’s espionage operations have compromised multiple government webmail tenants, enabling extensive data collection including stolen browser cookies and persistent implant check-ins. This facilitates unauthorized access to sensitive government communications and potentially other internal resources. Concurrently, their cryptocurrency fraud operations target Chinese-speaking users via SEO poisoning, likely resulting in financial losses. The dual nature of their operations increases the threat surface and complexity of defense.

Defensive Guidance

No specific patch or remediation is indicated for this threat. Defenders should focus on detecting and blocking the Antino backdoor, the malicious 'PDF Viewer' browser extension, and the ClientKing Linux/router implant. Monitoring for watering-hole attacks and suspicious browser cookie theft is advised. Since this is an APT group using custom implants and infrastructure, incident response should include network and endpoint forensics, and blocking known infrastructure associated with Jewelbug. Vendor advisories or patches are not applicable as this is a threat actor campaign rather than a software vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.security.com/blog-post/jewelbug-crypto-fraud-espionage"]
Adversary
REF7707
Pulse Id
6a7daa9c80273555f3d3ccd1

Indicators of Compromise

Ip

ValueDescriptionCopy
ip38.12.1.47
—
ip103.87.9.62
—
ip43.246.208.236
—
ip43.246.208.179
—
ip219.76.254.184
—

Domain

ValueDescriptionCopy
domainwww.jkskhei.com
—
domainns1.jkskhei.com
—
domainfonts.tarotfree101.top
—
domainfonts.chrorne.com
—
domainrobot.avbliud.com
—
domainmicrosoft-flash.com
—
domainwww.wps-cn.com
—
domainwww.f1ash.org.cn
—
domaineastus2.wac-azure.com
—
domainmailbycloud.com
—
domaindns.wizkidblogger.com
—

Hash

ValueDescriptionCopy
hashe6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf
—
hash01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a
—
hashe809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34
—
hashf1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8
—
hashe2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530
—
hashe7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb
—
hash09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff
—
hashc11714f9fe2df1ca906585c81498cd77f5ec05b132aab73fa3a71d71d71e42cc
—
hashb90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e
—
hash0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd
—
hash9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3
—
hash153d077bcb58e00f5746573cba25f6b0788b809bf7b2a52fca0dc22d3bb5c94e
—
hash297413a3e49e7353bf484a3eb15ec647de729211059df8fc68678d2378b6f561
—
hash30f5122cc199b9c2e524503b343a9ee13a6f9773dcbc1df82c8b25ad20bca61d
—
hash430f12970f8d58f12edccee9019a1aa90fa232c961449bdcc69c8d348a52cf55
—
hash5ccdf53881f6c758af8d94fe67066af209b4bc0a3cb80b6a4c724fad86eb97ef
—
hash5edb8d1023b8babf302871b68fa2b26d5ca57633f64951922998e8f1d6c8f7ac
—
hash6d5fe6b6a34eeb470798b970b70f41a07ccf59b22f49ad9b3dfff7aa3256f3c2
—
hash97c3a6be1711c5340d8806e4a54f7297f3f763d0aa4240b667f1e4e1f98f2aad
—
hashac3d453d3c9b0310ebb8a67cef35e2ac954d4acdf70cf497fe43a02c7a510813
—
hashe782a6d4919f194d41e524ebd6df5894197043cf772fcf60455127b246f302c0
—
hashea893abf20b00d9bfc042a88fbf7b4bd42e68ce07c116d3e3b002e5b4a853877
—
hashed96e7f1085a50251eb8967ac53777272a617831084f0edad8a769c583a18869
—
hashabfa7742e315485a98a5fafd6dbfb68e
—
hashbf681f76dc3b6f497d8c58e705585ae0
—
hashcc648bee6b11ce487565ef67576eb1c6
—
hash13425b473576aa1e58eee248e7c6a2e216889c58
—
hashe3b2bba523c035177241f6f66168e60fa6abbaaf
—

Url

ValueDescriptionCopy
urlhttps://microsoft-flash.com/download/flashcenter_pp_ax_install_en.exe
—
urlhttps://www.f1ash.org.cn/flashcenter_pp_ax_install_cn.exe
—
urlhttps://microsoft-flash.com/download/Adobeinstall.exe
—
urlhttps://fonts.chrorne.com/dist/js/12.qgfvjzvs.chunk.xn--js-02t
—

Threat ID: 6a7dc5f5bf8831d5393e2c19

Added to database: 08/13/2026, 13:26:13 UTC

Last enriched: 09/19/2026, 22:02:33 UTC

Last updated: 09/27/2026, 13:12:02 UTC

Views: 135

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses