Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'antino'

View all threats tagged with 'antino'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: antino

Threats Tagged 'antino'

Click on any threat for detailed analysis and mitigation recommendations

APT Group Runs Espionage and Crypto Fraud Operations Side by Side
0

Jewelbug is a China-based hackers-for-hire group conducting espionage against government ministries and militaries in the Middle East, Southeast Asia, and South Asia, while simultaneously running cryptocurrency fraud operations. They use a browser-centric remote-access framework called XG-Web to control their operations. Their main implant is the Antino backdoor, supported by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. A major operation compromised over 15 government webmail tenants in a Middle Eastern country via a watering-hole attack, resulting in over one million implant check-ins and 580,000 stolen browser cookies in three months. The operators are linked to a company registered in Hunan Province, China, and also conduct SEO poisoning targeting Chinese-speaking cryptocurrency users.

Join the discussion
China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business
0

Jewelbug is a China-based hackers-for-hire group conducting espionage campaigns against foreign governments and militaries, primarily in the Middle East, Southeast Asia, and South Asia, while simultaneously running a cryptocurrency fraud business. The group uses multiple implants including the Antino backdoor, a malicious browser extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. Between February and May 2026, they recorded over one million implant check-ins, stole more than 580,000 browser cookies, and exfiltrated over 2,300 emails. The financially motivated operations include industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites. The group operates with a structured development team and role-based access controls.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: antino
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses