China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business
Jewelbug is a China-based threat actor conducting dual operations: espionage campaigns targeting foreign governments and militaries, alongside a for-profit cryptocurrency fraud business administered from the same control panel. Operating as a small development team with role-based access controls and documented roadmaps, the group recorded over one million implant check-ins, 580,000+ stolen browser cookies, and 2,300+ exfiltrated emails between February and May 2026. Espionage attacks targeted government entities in the Middle East, Southeast Asia, and South Asia with confirmed intrusions. The group deploys the Antino backdoor, a malicious Chrome/Firefox extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. The financially motivated arm operates as a registered Hunan company running industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites.
AI Analysis
Technical Summary
Jewelbug is a dual-purpose China-based threat actor combining espionage and financially motivated cybercrime. Their espionage campaigns target foreign governments and militaries primarily in the Middle East, Southeast Asia, and South Asia, with confirmed intrusions. They deploy multiple malware components: Antino backdoor, a malicious Chrome/Firefox extension named 'PDF Viewer,' and ClientKing Linux implant targeting servers and routers. The financially motivated side runs an industrial-scale SEO poisoning operation funneling victims to fraudulent cryptocurrency exchange websites. The group operates as a small development team with role-based access controls and documented roadmaps. From February to May 2026, they recorded over one million implant check-ins, stole over 580,000 browser cookies, and exfiltrated more than 2,300 emails.
Potential Impact
The espionage operations compromise sensitive government and military information in multiple regions, potentially affecting national security. The theft of browser cookies and emails indicates significant data exfiltration capabilities. The cryptocurrency fraud business causes financial harm to victims, particularly Chinese-speaking users, through fake exchange sites. The dual nature of the group increases the complexity and scale of their operations, combining intelligence gathering with financially motivated cybercrime.
Mitigation Recommendations
No specific patches or fixes are indicated for this threat. Mitigation should focus on detecting and blocking the Antino backdoor, malicious browser extensions like 'PDF Viewer,' and the ClientKing implant. Organizations in targeted regions should enhance monitoring for indicators of compromise related to these tools. Users should be cautious of SEO poisoning leading to fraudulent cryptocurrency sites. Since this is a threat actor campaign rather than a software vulnerability, no direct patch is applicable.
Indicators of Compromise
- domain: juliangip.com
- domain: sttlink.com
- domain: bieqiang.xyz
- ip: 38.12.1.47
- domain: dm1.longmingdns.com
- domain: dm2.longmingdns.com
- domain: www.jkskhei.com
- domain: ns1.jkskhei.com
- hash: e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf
- hash: 01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a
- hash: e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34
- hash: f1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8
- hash: e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530
- hash: e7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb
- hash: 09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff
- hash: c11714f9fe2df1ca906585c81498cd77f5ec05b132aab73fa3a71d71d71e42cc
- hash: b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e
- hash: 0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd
- hash: 9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3
- hash: 153d077bcb58e00f5746573cba25f6b0788b809bf7b2a52fca0dc22d3bb5c94e
- hash: 297413a3e49e7353bf484a3eb15ec647de729211059df8fc68678d2378b6f561
- hash: 30f5122cc199b9c2e524503b343a9ee13a6f9773dcbc1df82c8b25ad20bca61d
- hash: 430f12970f8d58f12edccee9019a1aa90fa232c961449bdcc69c8d348a52cf55
- hash: 5ccdf53881f6c758af8d94fe67066af209b4bc0a3cb80b6a4c724fad86eb97ef
- hash: 5edb8d1023b8babf302871b68fa2b26d5ca57633f64951922998e8f1d6c8f7ac
- hash: 6d5fe6b6a34eeb470798b970b70f41a07ccf59b22f49ad9b3dfff7aa3256f3c2
- hash: 97c3a6be1711c5340d8806e4a54f7297f3f763d0aa4240b667f1e4e1f98f2aad
- hash: ac3d453d3c9b0310ebb8a67cef35e2ac954d4acdf70cf497fe43a02c7a510813
- hash: e782a6d4919f194d41e524ebd6df5894197043cf772fcf60455127b246f302c0
- hash: ea893abf20b00d9bfc042a88fbf7b4bd42e68ce07c116d3e3b002e5b4a853877
- hash: ed96e7f1085a50251eb8967ac53777272a617831084f0edad8a769c583a18869
- domain: fonts.tarotfree101.top
- domain: fonts.chrorne.com
- domain: robot.avbliud.com
- domain: microsoft-flash.com
- domain: www.wps-cn.com
- domain: www.f1ash.org.cn
- domain: eastus2.wac-azure.com
- domain: mailbycloud.com
- domain: dns.wizkidblogger.com
- ip: 103.87.9.62
- ip: 43.246.208.236
- ip: 43.246.208.179
- ip: 219.76.254.184
- url: https://fonts.chrorne.com/dist/js/12.qgfvjzvs.chunk.js
- hash: abfa7742e315485a98a5fafd6dbfb68e
- hash: bf681f76dc3b6f497d8c58e705585ae0
- hash: cc648bee6b11ce487565ef67576eb1c6
- hash: 13425b473576aa1e58eee248e7c6a2e216889c58
- hash: e3b2bba523c035177241f6f66168e60fa6abbaaf
- ip: 103.27.77.10
- ip: 195.172.120.227
- url: https://microsoft-flash.com/download/Adobeinstall.exe.
- domain: eoycqqcyix.com
- domain: haoxizhiye.com
- domain: jkskhei.com
- domain: tkstream123.com
- domain: usnbweb.mobi
- domain: aws.baidupi.top
- domain: xg.browser.fake.top
- domain: xg.browser.imitate.fishing
- domain: xg.exchange.automatic.fishing
- domain: xg.zalo.chat
China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business
Description
Jewelbug is a China-based threat actor conducting dual operations: espionage campaigns targeting foreign governments and militaries, alongside a for-profit cryptocurrency fraud business administered from the same control panel. Operating as a small development team with role-based access controls and documented roadmaps, the group recorded over one million implant check-ins, 580,000+ stolen browser cookies, and 2,300+ exfiltrated emails between February and May 2026. Espionage attacks targeted government entities in the Middle East, Southeast Asia, and South Asia with confirmed intrusions. The group deploys the Antino backdoor, a malicious Chrome/Firefox extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. The financially motivated arm operates as a registered Hunan company running industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Jewelbug is a dual-purpose China-based threat actor combining espionage and financially motivated cybercrime. Their espionage campaigns target foreign governments and militaries primarily in the Middle East, Southeast Asia, and South Asia, with confirmed intrusions. They deploy multiple malware components: Antino backdoor, a malicious Chrome/Firefox extension named 'PDF Viewer,' and ClientKing Linux implant targeting servers and routers. The financially motivated side runs an industrial-scale SEO poisoning operation funneling victims to fraudulent cryptocurrency exchange websites. The group operates as a small development team with role-based access controls and documented roadmaps. From February to May 2026, they recorded over one million implant check-ins, stole over 580,000 browser cookies, and exfiltrated more than 2,300 emails.
Potential Impact
The espionage operations compromise sensitive government and military information in multiple regions, potentially affecting national security. The theft of browser cookies and emails indicates significant data exfiltration capabilities. The cryptocurrency fraud business causes financial harm to victims, particularly Chinese-speaking users, through fake exchange sites. The dual nature of the group increases the complexity and scale of their operations, combining intelligence gathering with financially motivated cybercrime.
Defensive Guidance
No specific patches or fixes are indicated for this threat. Mitigation should focus on detecting and blocking the Antino backdoor, malicious browser extensions like 'PDF Viewer,' and the ClientKing implant. Organizations in targeted regions should enhance monitoring for indicators of compromise related to these tools. Users should be cautious of SEO poisoning leading to fraudulent cryptocurrency sites. Since this is a threat actor campaign rather than a software vulnerability, no direct patch is applicable.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://sed-cms.broadcom.com/sites/default/files/2026-08/Jewelbug%20Dossier.pdf"]
- Adversary
- REF7707
- Pulse Id
- 6a7da6cbe879002fadce7e53
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainjuliangip.com | — | |
domainsttlink.com | — | |
domainbieqiang.xyz | — | |
domaindm1.longmingdns.com | — | |
domaindm2.longmingdns.com | — | |
domainwww.jkskhei.com | — | |
domainns1.jkskhei.com | — | |
domainfonts.tarotfree101.top | — | |
domainfonts.chrorne.com | — | |
domainrobot.avbliud.com | — | |
domainmicrosoft-flash.com | — | |
domainwww.wps-cn.com | — | |
domainwww.f1ash.org.cn | — | |
domaineastus2.wac-azure.com | — | |
domainmailbycloud.com | — | |
domaindns.wizkidblogger.com | — | |
domaineoycqqcyix.com | — | |
domainhaoxizhiye.com | — | |
domainjkskhei.com | — | |
domaintkstream123.com | — | |
domainusnbweb.mobi | — | |
domainaws.baidupi.top | — | |
domainxg.browser.fake.top | — | |
domainxg.browser.imitate.fishing | — | |
domainxg.exchange.automatic.fishing | — | |
domainxg.zalo.chat | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip38.12.1.47 | — | |
ip103.87.9.62 | — | |
ip43.246.208.236 | — | |
ip43.246.208.179 | — | |
ip219.76.254.184 | — | |
ip103.27.77.10 | — | |
ip195.172.120.227 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hashe6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf | — | |
hash01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a | — | |
hashe809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34 | — | |
hashf1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8 | — | |
hashe2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530 | — | |
hashe7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb | — | |
hash09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff | — | |
hashc11714f9fe2df1ca906585c81498cd77f5ec05b132aab73fa3a71d71d71e42cc | — | |
hashb90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e | — | |
hash0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd | — | |
hash9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3 | — | |
hash153d077bcb58e00f5746573cba25f6b0788b809bf7b2a52fca0dc22d3bb5c94e | — | |
hash297413a3e49e7353bf484a3eb15ec647de729211059df8fc68678d2378b6f561 | — | |
hash30f5122cc199b9c2e524503b343a9ee13a6f9773dcbc1df82c8b25ad20bca61d | — | |
hash430f12970f8d58f12edccee9019a1aa90fa232c961449bdcc69c8d348a52cf55 | — | |
hash5ccdf53881f6c758af8d94fe67066af209b4bc0a3cb80b6a4c724fad86eb97ef | — | |
hash5edb8d1023b8babf302871b68fa2b26d5ca57633f64951922998e8f1d6c8f7ac | — | |
hash6d5fe6b6a34eeb470798b970b70f41a07ccf59b22f49ad9b3dfff7aa3256f3c2 | — | |
hash97c3a6be1711c5340d8806e4a54f7297f3f763d0aa4240b667f1e4e1f98f2aad | — | |
hashac3d453d3c9b0310ebb8a67cef35e2ac954d4acdf70cf497fe43a02c7a510813 | — | |
hashe782a6d4919f194d41e524ebd6df5894197043cf772fcf60455127b246f302c0 | — | |
hashea893abf20b00d9bfc042a88fbf7b4bd42e68ce07c116d3e3b002e5b4a853877 | — | |
hashed96e7f1085a50251eb8967ac53777272a617831084f0edad8a769c583a18869 | — | |
hashabfa7742e315485a98a5fafd6dbfb68e | — | |
hashbf681f76dc3b6f497d8c58e705585ae0 | — | |
hashcc648bee6b11ce487565ef67576eb1c6 | — | |
hash13425b473576aa1e58eee248e7c6a2e216889c58 | — | |
hashe3b2bba523c035177241f6f66168e60fa6abbaaf | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://fonts.chrorne.com/dist/js/12.qgfvjzvs.chunk.js | — | |
urlhttps://microsoft-flash.com/download/Adobeinstall.exe. | — |
Threat ID: 6a7dc5f5bf8831d5393e2bbb
Added to database: 08/13/2026, 13:26:13 UTC
Last enriched: 09/19/2026, 22:02:44 UTC
Last updated: 09/27/2026, 00:01:56 UTC
Views: 110
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.