Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Jewelbug is a China-based hackers-for-hire group conducting parallel operations: espionage campaigns targeting government ministries and militaries across the Middle East, Southeast Asia, and South Asia, alongside a cryptocurrency fraud business. Both missions operate from a single control panel called XG-Web, a browser-centric remote-access framework. The group's main implant is the Antino backdoor, complemented by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. Their largest operation compromised over 15 government webmail tenants in a Middle Eastern country through a single watering-hole attack. The victim database recorded over one million implant check-ins and 580,000 stolen browser cookies within three months. Operators are linked to a registered Hunan Province company, with infrastructure supporting both espionage and commercial SEO poisoning operations targeting Chinese-speaking cryptocurrency users.
AI Analysis
Technical Summary
Jewelbug is a hackers-for-hire APT group based in China that conducts parallel operations: espionage campaigns targeting government ministries and militaries across multiple Asian regions, and cryptocurrency fraud targeting Chinese-speaking users. Both operations are managed through a single control panel named XG-Web, a browser-centric remote-access framework. Their main implant is the Antino backdoor, supplemented by a malicious browser extension ('PDF Viewer') and the ClientKing implant targeting Linux routers. The group’s largest known campaign compromised over 15 government webmail tenants in a Middle Eastern country through a watering-hole attack, generating over one million implant check-ins and stealing 580,000 browser cookies within three months. The operators are linked to a company registered in Hunan Province, China, and their infrastructure supports both espionage and commercial SEO poisoning operations.
Potential Impact
The group’s espionage operations have compromised multiple government webmail tenants, enabling extensive data collection including stolen browser cookies and persistent implant check-ins. This facilitates unauthorized access to sensitive government communications and potentially other internal resources. Concurrently, their cryptocurrency fraud operations target Chinese-speaking users via SEO poisoning, likely resulting in financial losses. The dual nature of their operations increases the threat surface and complexity of defense.
Mitigation Recommendations
No specific patch or remediation is indicated for this threat. Defenders should focus on detecting and blocking the Antino backdoor, the malicious 'PDF Viewer' browser extension, and the ClientKing Linux/router implant. Monitoring for watering-hole attacks and suspicious browser cookie theft is advised. Since this is an APT group using custom implants and infrastructure, incident response should include network and endpoint forensics, and blocking known infrastructure associated with Jewelbug. Vendor advisories or patches are not applicable as this is a threat actor campaign rather than a software vulnerability.
Indicators of Compromise
- ip: 38.12.1.47
- domain: www.jkskhei.com
- domain: ns1.jkskhei.com
- hash: e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf
- hash: 01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a
- hash: e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34
- hash: f1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8
- hash: e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530
- hash: e7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb
- hash: 09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff
- hash: c11714f9fe2df1ca906585c81498cd77f5ec05b132aab73fa3a71d71d71e42cc
- hash: b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e
- hash: 0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd
- hash: 9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3
- hash: 153d077bcb58e00f5746573cba25f6b0788b809bf7b2a52fca0dc22d3bb5c94e
- hash: 297413a3e49e7353bf484a3eb15ec647de729211059df8fc68678d2378b6f561
- hash: 30f5122cc199b9c2e524503b343a9ee13a6f9773dcbc1df82c8b25ad20bca61d
- hash: 430f12970f8d58f12edccee9019a1aa90fa232c961449bdcc69c8d348a52cf55
- hash: 5ccdf53881f6c758af8d94fe67066af209b4bc0a3cb80b6a4c724fad86eb97ef
- hash: 5edb8d1023b8babf302871b68fa2b26d5ca57633f64951922998e8f1d6c8f7ac
- hash: 6d5fe6b6a34eeb470798b970b70f41a07ccf59b22f49ad9b3dfff7aa3256f3c2
- hash: 97c3a6be1711c5340d8806e4a54f7297f3f763d0aa4240b667f1e4e1f98f2aad
- hash: ac3d453d3c9b0310ebb8a67cef35e2ac954d4acdf70cf497fe43a02c7a510813
- hash: e782a6d4919f194d41e524ebd6df5894197043cf772fcf60455127b246f302c0
- hash: ea893abf20b00d9bfc042a88fbf7b4bd42e68ce07c116d3e3b002e5b4a853877
- hash: ed96e7f1085a50251eb8967ac53777272a617831084f0edad8a769c583a18869
- domain: fonts.tarotfree101.top
- domain: fonts.chrorne.com
- domain: robot.avbliud.com
- domain: microsoft-flash.com
- domain: www.wps-cn.com
- domain: www.f1ash.org.cn
- domain: eastus2.wac-azure.com
- domain: mailbycloud.com
- domain: dns.wizkidblogger.com
- ip: 103.87.9.62
- ip: 43.246.208.236
- ip: 43.246.208.179
- ip: 219.76.254.184
- url: https://microsoft-flash.com/download/flashcenter_pp_ax_install_en.exe
- url: https://www.f1ash.org.cn/flashcenter_pp_ax_install_cn.exe
- url: https://microsoft-flash.com/download/Adobeinstall.exe
- hash: abfa7742e315485a98a5fafd6dbfb68e
- hash: bf681f76dc3b6f497d8c58e705585ae0
- hash: cc648bee6b11ce487565ef67576eb1c6
- hash: 13425b473576aa1e58eee248e7c6a2e216889c58
- hash: e3b2bba523c035177241f6f66168e60fa6abbaaf
- url: https://fonts.chrorne.com/dist/js/12.qgfvjzvs.chunk.xn--js-02t
Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Description
Jewelbug is a China-based hackers-for-hire group conducting parallel operations: espionage campaigns targeting government ministries and militaries across the Middle East, Southeast Asia, and South Asia, alongside a cryptocurrency fraud business. Both missions operate from a single control panel called XG-Web, a browser-centric remote-access framework. The group's main implant is the Antino backdoor, complemented by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. Their largest operation compromised over 15 government webmail tenants in a Middle Eastern country through a single watering-hole attack. The victim database recorded over one million implant check-ins and 580,000 stolen browser cookies within three months. Operators are linked to a registered Hunan Province company, with infrastructure supporting both espionage and commercial SEO poisoning operations targeting Chinese-speaking cryptocurrency users.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Jewelbug is a hackers-for-hire APT group based in China that conducts parallel operations: espionage campaigns targeting government ministries and militaries across multiple Asian regions, and cryptocurrency fraud targeting Chinese-speaking users. Both operations are managed through a single control panel named XG-Web, a browser-centric remote-access framework. Their main implant is the Antino backdoor, supplemented by a malicious browser extension ('PDF Viewer') and the ClientKing implant targeting Linux routers. The group’s largest known campaign compromised over 15 government webmail tenants in a Middle Eastern country through a watering-hole attack, generating over one million implant check-ins and stealing 580,000 browser cookies within three months. The operators are linked to a company registered in Hunan Province, China, and their infrastructure supports both espionage and commercial SEO poisoning operations.
Potential Impact
The group’s espionage operations have compromised multiple government webmail tenants, enabling extensive data collection including stolen browser cookies and persistent implant check-ins. This facilitates unauthorized access to sensitive government communications and potentially other internal resources. Concurrently, their cryptocurrency fraud operations target Chinese-speaking users via SEO poisoning, likely resulting in financial losses. The dual nature of their operations increases the threat surface and complexity of defense.
Defensive Guidance
No specific patch or remediation is indicated for this threat. Defenders should focus on detecting and blocking the Antino backdoor, the malicious 'PDF Viewer' browser extension, and the ClientKing Linux/router implant. Monitoring for watering-hole attacks and suspicious browser cookie theft is advised. Since this is an APT group using custom implants and infrastructure, incident response should include network and endpoint forensics, and blocking known infrastructure associated with Jewelbug. Vendor advisories or patches are not applicable as this is a threat actor campaign rather than a software vulnerability.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.security.com/blog-post/jewelbug-crypto-fraud-espionage"]
- Adversary
- REF7707
- Pulse Id
- 6a7daa9c80273555f3d3ccd1
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip38.12.1.47 | — | |
ip103.87.9.62 | — | |
ip43.246.208.236 | — | |
ip43.246.208.179 | — | |
ip219.76.254.184 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainwww.jkskhei.com | — | |
domainns1.jkskhei.com | — | |
domainfonts.tarotfree101.top | — | |
domainfonts.chrorne.com | — | |
domainrobot.avbliud.com | — | |
domainmicrosoft-flash.com | — | |
domainwww.wps-cn.com | — | |
domainwww.f1ash.org.cn | — | |
domaineastus2.wac-azure.com | — | |
domainmailbycloud.com | — | |
domaindns.wizkidblogger.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hashe6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf | — | |
hash01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a | — | |
hashe809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34 | — | |
hashf1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8 | — | |
hashe2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530 | — | |
hashe7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb | — | |
hash09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff | — | |
hashc11714f9fe2df1ca906585c81498cd77f5ec05b132aab73fa3a71d71d71e42cc | — | |
hashb90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e | — | |
hash0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd | — | |
hash9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3 | — | |
hash153d077bcb58e00f5746573cba25f6b0788b809bf7b2a52fca0dc22d3bb5c94e | — | |
hash297413a3e49e7353bf484a3eb15ec647de729211059df8fc68678d2378b6f561 | — | |
hash30f5122cc199b9c2e524503b343a9ee13a6f9773dcbc1df82c8b25ad20bca61d | — | |
hash430f12970f8d58f12edccee9019a1aa90fa232c961449bdcc69c8d348a52cf55 | — | |
hash5ccdf53881f6c758af8d94fe67066af209b4bc0a3cb80b6a4c724fad86eb97ef | — | |
hash5edb8d1023b8babf302871b68fa2b26d5ca57633f64951922998e8f1d6c8f7ac | — | |
hash6d5fe6b6a34eeb470798b970b70f41a07ccf59b22f49ad9b3dfff7aa3256f3c2 | — | |
hash97c3a6be1711c5340d8806e4a54f7297f3f763d0aa4240b667f1e4e1f98f2aad | — | |
hashac3d453d3c9b0310ebb8a67cef35e2ac954d4acdf70cf497fe43a02c7a510813 | — | |
hashe782a6d4919f194d41e524ebd6df5894197043cf772fcf60455127b246f302c0 | — | |
hashea893abf20b00d9bfc042a88fbf7b4bd42e68ce07c116d3e3b002e5b4a853877 | — | |
hashed96e7f1085a50251eb8967ac53777272a617831084f0edad8a769c583a18869 | — | |
hashabfa7742e315485a98a5fafd6dbfb68e | — | |
hashbf681f76dc3b6f497d8c58e705585ae0 | — | |
hashcc648bee6b11ce487565ef67576eb1c6 | — | |
hash13425b473576aa1e58eee248e7c6a2e216889c58 | — | |
hashe3b2bba523c035177241f6f66168e60fa6abbaaf | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://microsoft-flash.com/download/flashcenter_pp_ax_install_en.exe | — | |
urlhttps://www.f1ash.org.cn/flashcenter_pp_ax_install_cn.exe | — | |
urlhttps://microsoft-flash.com/download/Adobeinstall.exe | — | |
urlhttps://fonts.chrorne.com/dist/js/12.qgfvjzvs.chunk.xn--js-02t | — |
Threat ID: 6a7dc5f5bf8831d5393e2c19
Added to database: 08/13/2026, 13:26:13 UTC
Last enriched: 09/19/2026, 22:02:33 UTC
Last updated: 09/27/2026, 13:12:02 UTC
Views: 135
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.