At a glance
- Actor or group: Jewelbug (suspected China-based threat group)
- Activity type: Cyber espionage and cryptocurrency fraud
- Targets or victims: Middle Eastern and Asian government ministries, aerospace firms, and crypto users
- Scale: Over 1 million implant check-ins and 580,000 stolen cookies
- Jurisdiction or law-enforcement status: Active espionage group; uncharged in this report
- Source: The Threat Hunter Team
TL;DR
The Threat Hunter Team discovered a dual-purpose campaign managed by the Jewelbug APT group. The operators conduct government espionage while simultaneously running a cryptocurrency fraud business. These distinct operations share a single command infrastructure and custom malware toolkit.
What happened
Security researchers uncovered a massive intrusion campaign targeting foreign governments. The attackers broke into networks using a malicious browser extension. Specifically, they disguised this tool as a PDF Viewer. The extension requested dangerous permissions to intercept web traffic and steal cookies. As a result, the operators bypassed browser sandboxes completely.
In addition to the browser extension, the attackers deployed the Antino backdoor. This Windows payload used the Microsoft Graph API for command-and-control communications. The attackers delivered this backdoor through fake software updates. Furthermore, the group utilized a Rust implant called ClientKing. This tool targeted Linux servers and consumer routers. The operators hid their traffic using domain name system tunneling.
During their largest attack, the hackers compromised a shared web-hosting platform. “In its largest operation, a single planted script placed a watering-hole on more than 15 government webmail tenants in a Middle Eastern country at once.” The script triggered a fake Adobe Flash update prompt. Subsequently, victims downloaded the Antino backdoor directly onto their devices.
Interestingly, the group used Google Docs for payload delivery. The backend system generated public documents containing obfuscated code. Implants then fetched these documents to execute the hidden payloads.

Who is behind it
Analysts attribute these Jewelbug APT group operations to Chinese-speaking hackers-for-hire. The researchers found strong connections to a registered company in Hunan Province, China. Investigators identified the sole legal representative using government-issued identity documents.
This individual operated under the online handle “paopaodada” or Bubble Boss. They ran a commercial search-ranking rental service on Telegram. “Both missions are administered from a single control panel, XG-Web, a browser-centric remote-access and information-stealing framework that turns a victim’s browser into a full remote-control channel and reaches from there into the host and the internal network behind it.”
However, investigators cannot confirm if the same person executed both missions. Instead, the commercial business likely provided infrastructure and access to the espionage team. The threat actors allegedly work from inside China. Their virtual private network routing bypassed domestic destinations. They primarily operated during afternoon and evening hours in the UTC+8 time zone.
Impact or scale
The scope of this cybercrime operation is staggering. The group maintained a massive victim database. “Jewelbug’s victim database recorded more than one million implant check-ins and more than 580,000 stolen browser cookies in less than three months of active operations.” The attackers also captured thousands of credentials and intercepted private email bodies.
Furthermore, the operators breached a major aerospace manufacturer. They configured specific implants to beacon through the company’s internal proxy. Meanwhile, the parallel crypto fraud operation generated thousands of fake exchange pages. The group used artificial intelligence to create phishing portals mimicking OKX and Binance.
These deceptive portals successfully lured Chinese-speaking cryptocurrency users. By placing watering-hole scripts on shared webmail platforms, the attackers compromised entire national estates at once. For an in-depth technical dive, you can read the Jewelbug APT group operations report.
What comes next or how readers can stay protected
This unique threat blends state-sponsored espionage with commodity crime. The dual-mission approach complicates traditional security monitoring. Organizations must secure shared hosting environments and audit third-party access.
Network administrators should monitor outbound traffic for unusual Microsoft Graph API usage. Check browsers for unapproved extensions requesting broad permissions. Enforce multi-factor authentication across all external access portals. Finally, employees should never download software updates from unofficial pop-up windows.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.