Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business

0
Medium
Published: 08/13/2026 (08/13/2026, 11:13:15 UTC)
Source: AlienVault OTX General

Description

Jewelbug is a China-based hackers-for-hire group conducting espionage campaigns against foreign governments and militaries, primarily in the Middle East, Southeast Asia, and South Asia, while simultaneously running a cryptocurrency fraud business. The group uses multiple implants including the Antino backdoor, a malicious browser extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. Between February and May 2026, they recorded over one million implant check-ins, stole more than 580,000 browser cookies, and exfiltrated over 2,300 emails. The financially motivated operations include industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites. The group operates with a structured development team and role-based access controls.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/13/2026, 17:31:40 UTC

Technical Analysis

Jewelbug is a dual-purpose China-based threat actor group engaging in espionage and financially motivated cybercrime. Their espionage targets include government entities in the Middle East, Southeast Asia, and South Asia, confirmed through intrusions. They deploy multiple malware implants: Antino backdoor, a malicious Chrome/Firefox extension named 'PDF Viewer,' and ClientKing targeting Linux servers and routers. The group’s cryptocurrency fraud business operates via a registered company in Hunan, China, leveraging SEO poisoning to direct victims to fraudulent crypto exchange sites. The group’s operations are sophisticated, with documented roadmaps and role-based access controls, and have resulted in significant data theft including browser cookies and emails. No known exploits in the wild or patches apply as this is a threat actor campaign rather than a software vulnerability.

Potential Impact

The espionage component compromises sensitive government and military information in targeted regions, potentially affecting national security. The cryptocurrency fraud business causes financial losses to victims, particularly Chinese-speaking users, through fake exchange sites. The group’s malware implants enable persistent access, data exfiltration, and browser hijacking, increasing the risk of credential theft and further compromise. The scale of implant check-ins and stolen data indicates a large and ongoing operation with significant impact on targeted entities and individuals.

Defensive Guidance

No specific patches or fixes apply as this is a threat actor campaign involving malware and social engineering rather than a software vulnerability. Defenders should focus on detection and blocking of the Antino backdoor, the malicious 'PDF Viewer' browser extension, and the ClientKing Linux implant. Monitoring for indicators of compromise from the referenced AlienVault dossier is recommended. Organizations in the targeted regions should enhance endpoint and network monitoring for unusual implant activity and educate users about fraudulent cryptocurrency sites and SEO poisoning tactics. Vendor advisories or official fixes are not applicable.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://sed-cms.broadcom.com/sites/default/files/2026-08/Jewelbug%20Dossier.pdf"]
Adversary
REF7707
Pulse Id
6a7da6cbe879002fadce7e53
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainjuliangip.com
domainsttlink.com
domainbieqiang.xyz
domaindm1.longmingdns.com
domaindm2.longmingdns.com
domainwww.jkskhei.com
domainns1.jkskhei.com
domainfonts.tarotfree101.top
domainfonts.chrorne.com
domainrobot.avbliud.com
domainmicrosoft-flash.com
domainwww.wps-cn.com
domainwww.f1ash.org.cn
domaineastus2.wac-azure.com
domainmailbycloud.com
domaindns.wizkidblogger.com
domaineoycqqcyix.com
domainhaoxizhiye.com
domainjkskhei.com
domaintkstream123.com
domainusnbweb.mobi
domainaws.baidupi.top
domainxg.browser.fake.top
domainxg.browser.imitate.fishing
domainxg.exchange.automatic.fishing
domainxg.zalo.chat

Ip

ValueDescriptionCopy
ip38.12.1.47
ip103.87.9.62
ip43.246.208.236
ip43.246.208.179
ip219.76.254.184
ip103.27.77.10
ip195.172.120.227

Hash

ValueDescriptionCopy
hashe6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf
hash01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a
hashe809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34
hashf1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8
hashe2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530
hashe7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb
hash09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff
hashc11714f9fe2df1ca906585c81498cd77f5ec05b132aab73fa3a71d71d71e42cc
hashb90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e
hash0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd
hash9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3
hash153d077bcb58e00f5746573cba25f6b0788b809bf7b2a52fca0dc22d3bb5c94e
hash297413a3e49e7353bf484a3eb15ec647de729211059df8fc68678d2378b6f561
hash30f5122cc199b9c2e524503b343a9ee13a6f9773dcbc1df82c8b25ad20bca61d
hash430f12970f8d58f12edccee9019a1aa90fa232c961449bdcc69c8d348a52cf55
hash5ccdf53881f6c758af8d94fe67066af209b4bc0a3cb80b6a4c724fad86eb97ef
hash5edb8d1023b8babf302871b68fa2b26d5ca57633f64951922998e8f1d6c8f7ac
hash6d5fe6b6a34eeb470798b970b70f41a07ccf59b22f49ad9b3dfff7aa3256f3c2
hash97c3a6be1711c5340d8806e4a54f7297f3f763d0aa4240b667f1e4e1f98f2aad
hashac3d453d3c9b0310ebb8a67cef35e2ac954d4acdf70cf497fe43a02c7a510813
hashe782a6d4919f194d41e524ebd6df5894197043cf772fcf60455127b246f302c0
hashea893abf20b00d9bfc042a88fbf7b4bd42e68ce07c116d3e3b002e5b4a853877
hashed96e7f1085a50251eb8967ac53777272a617831084f0edad8a769c583a18869
hashabfa7742e315485a98a5fafd6dbfb68e
hashbf681f76dc3b6f497d8c58e705585ae0
hashcc648bee6b11ce487565ef67576eb1c6
hash13425b473576aa1e58eee248e7c6a2e216889c58
hashe3b2bba523c035177241f6f66168e60fa6abbaaf

Url

ValueDescriptionCopy
urlhttps://fonts.chrorne.com/dist/js/12.qgfvjzvs.chunk.js
urlhttps://microsoft-flash.com/download/Adobeinstall.exe.

Threat ID: 6a7dc5f5bf8831d5393e2bbb

Added to database: 08/13/2026, 13:26:13 UTC

Last enriched: 08/13/2026, 17:31:40 UTC

Last updated: 08/13/2026, 17:57:56 UTC

Views: 11

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses