China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business
Jewelbug is a China-based hackers-for-hire group conducting espionage campaigns against foreign governments and militaries, primarily in the Middle East, Southeast Asia, and South Asia, while simultaneously running a cryptocurrency fraud business. The group uses multiple implants including the Antino backdoor, a malicious browser extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. Between February and May 2026, they recorded over one million implant check-ins, stole more than 580,000 browser cookies, and exfiltrated over 2,300 emails. The financially motivated operations include industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites. The group operates with a structured development team and role-based access controls.
AI Analysis
Technical Summary
Jewelbug is a dual-purpose China-based threat actor group engaging in espionage and financially motivated cybercrime. Their espionage targets include government entities in the Middle East, Southeast Asia, and South Asia, confirmed through intrusions. They deploy multiple malware implants: Antino backdoor, a malicious Chrome/Firefox extension named 'PDF Viewer,' and ClientKing targeting Linux servers and routers. The group’s cryptocurrency fraud business operates via a registered company in Hunan, China, leveraging SEO poisoning to direct victims to fraudulent crypto exchange sites. The group’s operations are sophisticated, with documented roadmaps and role-based access controls, and have resulted in significant data theft including browser cookies and emails. No known exploits in the wild or patches apply as this is a threat actor campaign rather than a software vulnerability.
Potential Impact
The espionage component compromises sensitive government and military information in targeted regions, potentially affecting national security. The cryptocurrency fraud business causes financial losses to victims, particularly Chinese-speaking users, through fake exchange sites. The group’s malware implants enable persistent access, data exfiltration, and browser hijacking, increasing the risk of credential theft and further compromise. The scale of implant check-ins and stolen data indicates a large and ongoing operation with significant impact on targeted entities and individuals.
Mitigation Recommendations
No specific patches or fixes apply as this is a threat actor campaign involving malware and social engineering rather than a software vulnerability. Defenders should focus on detection and blocking of the Antino backdoor, the malicious 'PDF Viewer' browser extension, and the ClientKing Linux implant. Monitoring for indicators of compromise from the referenced AlienVault dossier is recommended. Organizations in the targeted regions should enhance endpoint and network monitoring for unusual implant activity and educate users about fraudulent cryptocurrency sites and SEO poisoning tactics. Vendor advisories or official fixes are not applicable.
Indicators of Compromise
- domain: juliangip.com
- domain: sttlink.com
- domain: bieqiang.xyz
- ip: 38.12.1.47
- domain: dm1.longmingdns.com
- domain: dm2.longmingdns.com
- domain: www.jkskhei.com
- domain: ns1.jkskhei.com
- hash: e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf
- hash: 01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a
- hash: e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34
- hash: f1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8
- hash: e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530
- hash: e7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb
- hash: 09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff
- hash: c11714f9fe2df1ca906585c81498cd77f5ec05b132aab73fa3a71d71d71e42cc
- hash: b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e
- hash: 0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd
- hash: 9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3
- hash: 153d077bcb58e00f5746573cba25f6b0788b809bf7b2a52fca0dc22d3bb5c94e
- hash: 297413a3e49e7353bf484a3eb15ec647de729211059df8fc68678d2378b6f561
- hash: 30f5122cc199b9c2e524503b343a9ee13a6f9773dcbc1df82c8b25ad20bca61d
- hash: 430f12970f8d58f12edccee9019a1aa90fa232c961449bdcc69c8d348a52cf55
- hash: 5ccdf53881f6c758af8d94fe67066af209b4bc0a3cb80b6a4c724fad86eb97ef
- hash: 5edb8d1023b8babf302871b68fa2b26d5ca57633f64951922998e8f1d6c8f7ac
- hash: 6d5fe6b6a34eeb470798b970b70f41a07ccf59b22f49ad9b3dfff7aa3256f3c2
- hash: 97c3a6be1711c5340d8806e4a54f7297f3f763d0aa4240b667f1e4e1f98f2aad
- hash: ac3d453d3c9b0310ebb8a67cef35e2ac954d4acdf70cf497fe43a02c7a510813
- hash: e782a6d4919f194d41e524ebd6df5894197043cf772fcf60455127b246f302c0
- hash: ea893abf20b00d9bfc042a88fbf7b4bd42e68ce07c116d3e3b002e5b4a853877
- hash: ed96e7f1085a50251eb8967ac53777272a617831084f0edad8a769c583a18869
- domain: fonts.tarotfree101.top
- domain: fonts.chrorne.com
- domain: robot.avbliud.com
- domain: microsoft-flash.com
- domain: www.wps-cn.com
- domain: www.f1ash.org.cn
- domain: eastus2.wac-azure.com
- domain: mailbycloud.com
- domain: dns.wizkidblogger.com
- ip: 103.87.9.62
- ip: 43.246.208.236
- ip: 43.246.208.179
- ip: 219.76.254.184
- url: https://fonts.chrorne.com/dist/js/12.qgfvjzvs.chunk.js
- hash: abfa7742e315485a98a5fafd6dbfb68e
- hash: bf681f76dc3b6f497d8c58e705585ae0
- hash: cc648bee6b11ce487565ef67576eb1c6
- hash: 13425b473576aa1e58eee248e7c6a2e216889c58
- hash: e3b2bba523c035177241f6f66168e60fa6abbaaf
- ip: 103.27.77.10
- ip: 195.172.120.227
- url: https://microsoft-flash.com/download/Adobeinstall.exe.
- domain: eoycqqcyix.com
- domain: haoxizhiye.com
- domain: jkskhei.com
- domain: tkstream123.com
- domain: usnbweb.mobi
- domain: aws.baidupi.top
- domain: xg.browser.fake.top
- domain: xg.browser.imitate.fishing
- domain: xg.exchange.automatic.fishing
- domain: xg.zalo.chat
China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business
Description
Jewelbug is a China-based hackers-for-hire group conducting espionage campaigns against foreign governments and militaries, primarily in the Middle East, Southeast Asia, and South Asia, while simultaneously running a cryptocurrency fraud business. The group uses multiple implants including the Antino backdoor, a malicious browser extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. Between February and May 2026, they recorded over one million implant check-ins, stole more than 580,000 browser cookies, and exfiltrated over 2,300 emails. The financially motivated operations include industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites. The group operates with a structured development team and role-based access controls.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Jewelbug is a dual-purpose China-based threat actor group engaging in espionage and financially motivated cybercrime. Their espionage targets include government entities in the Middle East, Southeast Asia, and South Asia, confirmed through intrusions. They deploy multiple malware implants: Antino backdoor, a malicious Chrome/Firefox extension named 'PDF Viewer,' and ClientKing targeting Linux servers and routers. The group’s cryptocurrency fraud business operates via a registered company in Hunan, China, leveraging SEO poisoning to direct victims to fraudulent crypto exchange sites. The group’s operations are sophisticated, with documented roadmaps and role-based access controls, and have resulted in significant data theft including browser cookies and emails. No known exploits in the wild or patches apply as this is a threat actor campaign rather than a software vulnerability.
Potential Impact
The espionage component compromises sensitive government and military information in targeted regions, potentially affecting national security. The cryptocurrency fraud business causes financial losses to victims, particularly Chinese-speaking users, through fake exchange sites. The group’s malware implants enable persistent access, data exfiltration, and browser hijacking, increasing the risk of credential theft and further compromise. The scale of implant check-ins and stolen data indicates a large and ongoing operation with significant impact on targeted entities and individuals.
Defensive Guidance
No specific patches or fixes apply as this is a threat actor campaign involving malware and social engineering rather than a software vulnerability. Defenders should focus on detection and blocking of the Antino backdoor, the malicious 'PDF Viewer' browser extension, and the ClientKing Linux implant. Monitoring for indicators of compromise from the referenced AlienVault dossier is recommended. Organizations in the targeted regions should enhance endpoint and network monitoring for unusual implant activity and educate users about fraudulent cryptocurrency sites and SEO poisoning tactics. Vendor advisories or official fixes are not applicable.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://sed-cms.broadcom.com/sites/default/files/2026-08/Jewelbug%20Dossier.pdf"]
- Adversary
- REF7707
- Pulse Id
- 6a7da6cbe879002fadce7e53
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainjuliangip.com | — | |
domainsttlink.com | — | |
domainbieqiang.xyz | — | |
domaindm1.longmingdns.com | — | |
domaindm2.longmingdns.com | — | |
domainwww.jkskhei.com | — | |
domainns1.jkskhei.com | — | |
domainfonts.tarotfree101.top | — | |
domainfonts.chrorne.com | — | |
domainrobot.avbliud.com | — | |
domainmicrosoft-flash.com | — | |
domainwww.wps-cn.com | — | |
domainwww.f1ash.org.cn | — | |
domaineastus2.wac-azure.com | — | |
domainmailbycloud.com | — | |
domaindns.wizkidblogger.com | — | |
domaineoycqqcyix.com | — | |
domainhaoxizhiye.com | — | |
domainjkskhei.com | — | |
domaintkstream123.com | — | |
domainusnbweb.mobi | — | |
domainaws.baidupi.top | — | |
domainxg.browser.fake.top | — | |
domainxg.browser.imitate.fishing | — | |
domainxg.exchange.automatic.fishing | — | |
domainxg.zalo.chat | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip38.12.1.47 | — | |
ip103.87.9.62 | — | |
ip43.246.208.236 | — | |
ip43.246.208.179 | — | |
ip219.76.254.184 | — | |
ip103.27.77.10 | — | |
ip195.172.120.227 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hashe6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf | — | |
hash01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a | — | |
hashe809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34 | — | |
hashf1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8 | — | |
hashe2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530 | — | |
hashe7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb | — | |
hash09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff | — | |
hashc11714f9fe2df1ca906585c81498cd77f5ec05b132aab73fa3a71d71d71e42cc | — | |
hashb90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e | — | |
hash0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd | — | |
hash9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3 | — | |
hash153d077bcb58e00f5746573cba25f6b0788b809bf7b2a52fca0dc22d3bb5c94e | — | |
hash297413a3e49e7353bf484a3eb15ec647de729211059df8fc68678d2378b6f561 | — | |
hash30f5122cc199b9c2e524503b343a9ee13a6f9773dcbc1df82c8b25ad20bca61d | — | |
hash430f12970f8d58f12edccee9019a1aa90fa232c961449bdcc69c8d348a52cf55 | — | |
hash5ccdf53881f6c758af8d94fe67066af209b4bc0a3cb80b6a4c724fad86eb97ef | — | |
hash5edb8d1023b8babf302871b68fa2b26d5ca57633f64951922998e8f1d6c8f7ac | — | |
hash6d5fe6b6a34eeb470798b970b70f41a07ccf59b22f49ad9b3dfff7aa3256f3c2 | — | |
hash97c3a6be1711c5340d8806e4a54f7297f3f763d0aa4240b667f1e4e1f98f2aad | — | |
hashac3d453d3c9b0310ebb8a67cef35e2ac954d4acdf70cf497fe43a02c7a510813 | — | |
hashe782a6d4919f194d41e524ebd6df5894197043cf772fcf60455127b246f302c0 | — | |
hashea893abf20b00d9bfc042a88fbf7b4bd42e68ce07c116d3e3b002e5b4a853877 | — | |
hashed96e7f1085a50251eb8967ac53777272a617831084f0edad8a769c583a18869 | — | |
hashabfa7742e315485a98a5fafd6dbfb68e | — | |
hashbf681f76dc3b6f497d8c58e705585ae0 | — | |
hashcc648bee6b11ce487565ef67576eb1c6 | — | |
hash13425b473576aa1e58eee248e7c6a2e216889c58 | — | |
hashe3b2bba523c035177241f6f66168e60fa6abbaaf | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://fonts.chrorne.com/dist/js/12.qgfvjzvs.chunk.js | — | |
urlhttps://microsoft-flash.com/download/Adobeinstall.exe. | — |
Threat ID: 6a7dc5f5bf8831d5393e2bbb
Added to database: 08/13/2026, 13:26:13 UTC
Last enriched: 08/13/2026, 17:31:40 UTC
Last updated: 08/13/2026, 17:57:56 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.