The Jewelbug webmail espionage campaign, in which a single malicious script injected into a shared government mail platform compromised accounts across 15 separate tenants, was run in parallel with what researchers describe as an industrial-scale cryptocurrency fraud operation, with both activities managed from the same control panel. Jewelbug, also tracked as Earth Alux and REF7707, has been active since at least the second quarter of 2023, according to TechTimes, making this a sustained operation rather than an opportunistic burst.

Researchers at Symantec uncovered the campaign while tracing infections of the group’s Antino backdoor back to Jewelbug’s infrastructure. That access gave them visibility into the C2 management platform, database, server logs, source code, and operator files, in effect, a window into the group’s full toolkit and victim list.

How the Jewelbug Webmail Espionage Campaign Worked

The entry point was a shared web-hosting platform operated by a state telecommunications provider and national services agency. After gaining write access to that platform, Jewelbug inserted a malicious script into the common template of the webmail installation. From there, the attack scaled automatically: the script ran on login pages and mailbox views for every one of the 15 government tenants sharing the platform, covering nine government domains.

Each time a user logged in, the JavaScript payload opened a WebSocket connection to the attacker’s command-and-control server. The script exfiltrated webmail cookies and retrieved the user’s email address to check whether it belonged to a targeted government domain. Those that did were served a fake Adobe Flash update prompt, which installed the Antino backdoor on Windows along with browser tooling.

Symantec notes that Antino is also delivered through malicious HTA files and fake Adobe or Flash installers, and is used to deploy additional payloads. One of these is a malicious browser extension for Chrome and Firefox, named PDF Viewer, which steals cookies and credentials, intercepts traffic, injects JavaScript, and remotely exposes browser functions. Alongside Antino, the group also uses a framework called XG-Web for managing campaigns and victim information.

A separate implant, the Rust-based ClientKing, targets Linux servers, ARM64 devices, and ASUS routers, supporting command execution, SOCKS proxying, DNS tunnelling, and in-memory kernel module loading. To help malicious traffic blend with legitimate services, Jewelbug used public Google Docs to host obfuscated payloads retrieved and executed by their implants.

Scale of the Operation and the Cryptocurrency Fraud

The raw numbers from Jewelbug’s own infrastructure tell the scale of the Jewelbug webmail espionage campaign and its financial wing clearly. The group’s victim database holds more than one million implant check-in rows, more than 580,000 stolen browser cookies, several thousand captured credentials, and more than 2,300 exfiltrated email bodies, according to Symantec researchers.

On the espionage side, Symantec recorded roughly 1.1 million geolocation events against approximately 4,300 distinct source IP addresses. Approximately 87,200 connections came from a Southeast Asian country targeting state telecom and military networks; approximately 53,100 from a Middle Eastern country, including Starlink-connected addresses in the capital; and approximately 15,000 from a second Southeast Asian country, including government ministry infrastructure. Targets span the Middle East, Southeast Asia, South Asia, and Taiwan, Crypto Briefing reports, with sectors including defence, telecommunications, education, and aviation.

The cryptocurrency fraud operation runs on an automated pipeline that scrapes keywords, generates thousands of fake download pages using AI, and publishes them across a 44-server content-management fleet and hundreds of lookalike domains impersonating OKX and Binance. AI-generated articles drive traffic to fake crypto exchange sites, while click-fraud bots manipulate search rankings to promote fraudulent pages. The lures extend beyond crypto: sports betting, pirated livestream portals, and private detective scams are also in the mix.

The financially motivated side of these operations points toward a hack-for-hire dimension. Symantec researchers say they have high confidence attributing Jewelbug’s financially motivated activities to a Chinese company that advertises SEO services. TechTimes further reports that at least one of the group’s operators is linked, via government-issued identity documents, to a registered company in Changsha, Hunan Province, a detail that puts a specific geographic anchor on what has otherwise been a carefully obscured operation.

What Symantec Has Published

Symantec has released indicators of compromise related to observed Jewelbug activity alongside a more detailed technical report covering the group’s tooling and tradecraft, its financial operation, and the infrastructure used in attacks. The dual nature of the campaign (state-aligned espionage and commercial cybercrime running on a shared platform) is what Symantec describes as an “industrial-scale cryptocurrency fraud business” sitting alongside the intelligence-gathering work, a combination that suggests the group’s operators are running both for profit and for patrons.

Share.

Software engineer and video game uber-nerd.

Comments are closed.

Exit mobile version