Symantec researchers identified a Chinese hackers-for-hire group dubbed "Jewelbug" that runs both nation-state cyber espionage and financially motivated cryptocurrency theft from a single custom command-and-control panel called XG-Web. The group deploys custom malware including a Windows backdoor (Antino), a Linux backdoor (ClientKing), and a malicious browser extension disguised as a PDF viewer that steals cookies, session tokens, and browsing history while allowing sandbox escape and arbitrary JavaScript injection. Victims include government, military, and telecom organizations across Asia and the Middle East, a US aerospace manufacturer, and thousands of cryptocurrency phishing victims, with researchers finding over 580,000 stolen browser cookie jars and thousands of exfiltrated credentials.

6m read timeFrom darkreading.com
Post cover image
Table of contents
Jewelbug's Tools and TTPsJewelbug's Victims: Government, Military, and CorporateOutsourced International Cyber Espionage

Questions this post answers

What is the Jewelbug APT group and what does it do?

Jewelbug is a China-based hackers-for-hire group that runs both nation-state cyber espionage and financially motivated cryptocurrency theft from the same custom command-and-control panel, called XG-Web. It has compromised government, military, and telecommunications organizations across Asia and the Middle East, plus a major US aerospace manufacturer, while also running hundreds of fake cryptocurrency exchanges using AI-generated phishing sites. Security teams tracking emerging APT groups follow threat intelligence like this on daily.dev.

How does the fake PDF Viewer browser extension malware work?

The malicious browser extension, disguised as a PDF viewer, requests every possible browser permission and then steals cookies, session tokens, browsing history, screenshots, and traffic. It also lets attackers escape the browser sandbox, inject arbitrary JavaScript into any webpage, control the victim's browser remotely, and includes an unused feature to silently swap cryptocurrency wallet addresses during transactions. Developers building browser extensions can watch for malware analysis like this on daily.dev to harden their own security posture.

What is the scale of data stolen in the Jewelbug cyberattacks?

Researchers found more than 580,000 full browser cookie jars, 2,300 fully exfiltrated email bodies, and several thousand login credentials in the group's infrastructure, representing thousands of distinct victims. The group managed its operations through role-based access controls with superadmin, admin, and ordinary user tiers across a fleet of 44 content management servers. Incident responders assessing breach scope track threat actor case studies like this via daily.dev.

224 Impressions