<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/jewelbug-apt-balances-state-espionage-cryptocurrency-theft-zldza7t5k" -->

---
title: &#x27;Jewelbug&#x27; APT Balances State Espionage &amp; Cryptocurrency...
description: Symantec researchers identified a Chinese hackers-for-hire group dubbed &quot;Jewelbug&quot; that runs both nation-state cyber espionage and financially motivated...
canonical: https://daily.dev/posts/jewelbug-apt-balances-state-espionage-cryptocurrency-theft-zldza7t5k
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: &#x27;Jewelbug&#x27; APT Balances State Espionage &amp; Cryptocurrency Theft | daily.dev
og:description: Symantec researchers identified a Chinese hackers-for-hire group dubbed &quot;Jewelbug&quot; that runs both nation-state cyber espionage and financially motivated...
og:url: https://daily.dev/posts/jewelbug-apt-balances-state-espionage-cryptocurrency-theft-zldza7t5k
og:image: https://api.daily.dev/og/posts/zLdZa7t5k.png
og:image:alt: &#x27;Jewelbug&#x27; APT Balances State Espionage &amp; Cryptocurrency Theft
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# 'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft

**[Dark Reading](https://daily.dev/sources/dr)** · 6 min read · 0 upvotes · 0 comments

## Summary

Symantec researchers identified a Chinese hackers-for-hire group dubbed "Jewelbug" that runs both nation-state cyber espionage and financially motivated cryptocurrency theft from a single custom command-and-control panel called XG-Web. The group deploys custom malware including a Windows backdoor (Antino), a Linux backdoor (ClientKing), and a malicious browser extension disguised as a PDF viewer that steals cookies, session tokens, and browsing history while allowing sandbox escape and arbitrary JavaScript injection. Victims include government, military, and telecom organizations across Asia and the Middle East, a US aerospace manufacturer, and thousands of cryptocurrency phishing victims, with researchers finding over 580,000 stolen browser cookie jars and thousands of exfiltrated credentials.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.darkreading.com/threat-intelligence/jewelbug-apt-state-espionage-cryptocurrency-theft>

## Questions this post answers

### What is the Jewelbug APT group and what does it do?

Jewelbug is a China-based hackers-for-hire group that runs both nation-state cyber espionage and financially motivated cryptocurrency theft from the same custom command-and-control panel, called XG-Web. It has compromised government, military, and telecommunications organizations across Asia and the Middle East, plus a major US aerospace manufacturer, while also running hundreds of fake cryptocurrency exchanges using AI-generated phishing sites.

_Security teams tracking emerging APT groups follow threat intelligence like this on daily.dev._

### How does the fake PDF Viewer browser extension malware work?

The malicious browser extension, disguised as a PDF viewer, requests every possible browser permission and then steals cookies, session tokens, browsing history, screenshots, and traffic. It also lets attackers escape the browser sandbox, inject arbitrary JavaScript into any webpage, control the victim's browser remotely, and includes an unused feature to silently swap cryptocurrency wallet addresses during transactions.

_Developers building browser extensions can watch for malware analysis like this on daily.dev to harden their own security posture._

### What is the scale of data stolen in the Jewelbug cyberattacks?

Researchers found more than 580,000 full browser cookie jars, 2,300 fully exfiltrated email bodies, and several thousand login credentials in the group's infrastructure, representing thousands of distinct victims. The group managed its operations through role-based access controls with superadmin, admin, and ordinary user tiers across a fleet of 44 content management servers.

_Incident responders assessing breach scope track threat actor case studies like this via daily.dev._

## Similar posts on daily.dev

- [Chinese Threat Group 'Jewelbug' Quietly Infiltrated Russian IT Network for Months](https://daily.dev/posts/chinese-threat-group-jewelbug-quietly-infiltrated-russian-it-network-for-months-vlrpby4vz) · The Hacker News · 1 upvotes · 0 comments
- [Chinese cyberspies compromised Russian tech provider](https://daily.dev/posts/chinese-cyberspies-compromised-russian-tech-provider-kxuhvsgxq) · The Register · 1 upvotes · 0 comments

---

Tags: [#devtools](https://daily.dev/tags/devtools), [#crypto](https://daily.dev/tags/crypto), [#malware](https://daily.dev/tags/malware), [#phishing](https://daily.dev/tags/phishing)

[View this post on daily.dev](https://daily.dev/posts/jewelbug-apt-balances-state-espionage-cryptocurrency-theft-zldza7t5k)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft","url":"https://daily.dev/posts/jewelbug-apt-balances-state-espionage-cryptocurrency-theft-zldza7t5k","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/jewelbug-apt-balances-state-espionage-cryptocurrency-theft-zldza7t5k"},"datePublished":"2026-08-13T10:03:53.678Z","dateModified":"2026-08-13T10:04:21.576Z","description":"Symantec researchers identified a Chinese hackers-for-hire group dubbed \"Jewelbug\" that runs both nation-state cyber espionage and financially motivated...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/c0773c6cf743c126bf4ae5297a71f588?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/c0773c6cf743c126bf4ae5297a71f588?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Dark Reading","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Dark Reading","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/dr","url":"https://daily.dev/sources/dr"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/jewelbug-apt-balances-state-espionage-cryptocurrency-theft-zldza7t5k","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"devtools,crypto,malware,phishing","timeRequired":"PT6M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Dark Reading","item":"https://daily.dev/sources/dr"},{"@type":"ListItem","position":3,"name":"'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/jewelbug-apt-balances-state-espionage-cryptocurrency-theft-zldza7t5k#faq","mainEntity":[{"@type":"Question","name":"What is the Jewelbug APT group and what does it do?","acceptedAnswer":{"@type":"Answer","text":"Jewelbug is a China-based hackers-for-hire group that runs both nation-state cyber espionage and financially motivated cryptocurrency theft from the same custom command-and-control panel, called XG-Web. It has compromised government, military, and telecommunications organizations across Asia and the Middle East, plus a major US aerospace manufacturer, while also running hundreds of fake cryptocurrency exchanges using AI-generated phishing sites. Security teams tracking emerging APT groups follow threat intelligence like this on daily.dev."}},{"@type":"Question","name":"How does the fake PDF Viewer browser extension malware work?","acceptedAnswer":{"@type":"Answer","text":"The malicious browser extension, disguised as a PDF viewer, requests every possible browser permission and then steals cookies, session tokens, browsing history, screenshots, and traffic. It also lets attackers escape the browser sandbox, inject arbitrary JavaScript into any webpage, control the victim's browser remotely, and includes an unused feature to silently swap cryptocurrency wallet addresses during transactions. Developers building browser extensions can watch for malware analysis like this on daily.dev to harden their own security posture."}},{"@type":"Question","name":"What is the scale of data stolen in the Jewelbug cyberattacks?","acceptedAnswer":{"@type":"Answer","text":"Researchers found more than 580,000 full browser cookie jars, 2,300 fully exfiltrated email bodies, and several thousand login credentials in the group's infrastructure, representing thousands of distinct victims. The group managed its operations through role-based access controls with superadmin, admin, and ordinary user tiers across a fleet of 44 content management servers. Incident responders assessing breach scope track threat actor case studies like this via daily.dev."}}]}
```

