Threats Tagged 'pdf viewer'
View all threats tagged with 'pdf viewer'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'pdf viewer'
Click on any threat for detailed analysis and mitigation recommendations
APT Group Runs Espionage and Crypto Fraud Operations Side by Side 0 Jewelbug is a China-based hackers-for-hire group conducting espionage against government ministries and militaries in the Middle East, Southeast Asia, and South Asia, while simultaneously running cryptocurrency fraud operations. They use a browser-centric remote-access framework called XG-Web to control their operations. Their main implant is the Antino backdoor, supported by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. A major operation compromised over 15 government webmail tenants in a Middle Eastern country via a watering-hole attack, resulting in over one million implant check-ins and 580,000 stolen browser cookies in three months. The operators are linked to a company registered in Hunan Province, China, and also conduct SEO poisoning targeting Chinese-speaking cryptocurrency users. Join the discussion | AlienVault OTX General | 08/13/2026, 11:29:32 UTC Added: 08/13/2026, 13:26:13 UTC |
China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business 0 Jewelbug is a China-based hackers-for-hire group conducting espionage campaigns against foreign governments and militaries, primarily in the Middle East, Southeast Asia, and South Asia, while simultaneously running a cryptocurrency fraud business. The group uses multiple implants including the Antino backdoor, a malicious browser extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. Between February and May 2026, they recorded over one million implant check-ins, stole more than 580,000 browser cookies, and exfiltrated over 2,300 emails. The financially motivated operations include industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites. The group operates with a structured development team and role-based access controls. Join the discussion | AlienVault OTX General | 08/13/2026, 11:13:15 UTC Added: 08/13/2026, 13:26:13 UTC |
Showing 1 to 2 of 2 results