Close Menu
Mozbot
    Facebook X (Twitter) Instagram
    Button
    MozbotMozbot
    Facebook X (Twitter) Instagram YouTube
    • About us
    • Technology
    • Gadgets
    • Apps & Software
      • Computing
    • News
    • Contact Us
    • Article Submissions
    Mozbot
    Home » News » Jewelbug Webmail Espionage Campaign Hit 15 Govt Tenants via Single Script
    Technology

    Jewelbug Webmail Espionage Campaign Hit 15 Govt Tenants via Single Script

    Gary BehanBy Gary Behan17/08/2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    Jewelbug webmail espionage campaign
    Share
    Facebook Twitter Pinterest Reddit WhatsApp Email

    The Jewelbug webmail espionage campaign, in which a single malicious script injected into a shared government mail platform compromised accounts across 15 separate tenants, was run in parallel with what researchers describe as an industrial-scale cryptocurrency fraud operation, with both activities managed from the same control panel. Jewelbug, also tracked as Earth Alux and REF7707, has been active since at least the second quarter of 2023, according to TechTimes, making this a sustained operation rather than an opportunistic burst.

    Researchers at Symantec uncovered the campaign while tracing infections of the group’s Antino backdoor back to Jewelbug’s infrastructure. That access gave them visibility into the C2 management platform, database, server logs, source code, and operator files, in effect, a window into the group’s full toolkit and victim list.

    How the Jewelbug Webmail Espionage Campaign Worked

    The entry point was a shared web-hosting platform operated by a state telecommunications provider and national services agency. After gaining write access to that platform, Jewelbug inserted a malicious script into the common template of the webmail installation. From there, the attack scaled automatically: the script ran on login pages and mailbox views for every one of the 15 government tenants sharing the platform, covering nine government domains.

    Each time a user logged in, the JavaScript payload opened a WebSocket connection to the attacker’s command-and-control server. The script exfiltrated webmail cookies and retrieved the user’s email address to check whether it belonged to a targeted government domain. Those that did were served a fake Adobe Flash update prompt, which installed the Antino backdoor on Windows along with browser tooling.

    Symantec notes that Antino is also delivered through malicious HTA files and fake Adobe or Flash installers, and is used to deploy additional payloads. One of these is a malicious browser extension for Chrome and Firefox, named PDF Viewer, which steals cookies and credentials, intercepts traffic, injects JavaScript, and remotely exposes browser functions. Alongside Antino, the group also uses a framework called XG-Web for managing campaigns and victim information.

    A separate implant, the Rust-based ClientKing, targets Linux servers, ARM64 devices, and ASUS routers, supporting command execution, SOCKS proxying, DNS tunnelling, and in-memory kernel module loading. To help malicious traffic blend with legitimate services, Jewelbug used public Google Docs to host obfuscated payloads retrieved and executed by their implants.

    Scale of the Operation and the Cryptocurrency Fraud

    The raw numbers from Jewelbug’s own infrastructure tell the scale of the Jewelbug webmail espionage campaign and its financial wing clearly. The group’s victim database holds more than one million implant check-in rows, more than 580,000 stolen browser cookies, several thousand captured credentials, and more than 2,300 exfiltrated email bodies, according to Symantec researchers.

    On the espionage side, Symantec recorded roughly 1.1 million geolocation events against approximately 4,300 distinct source IP addresses. Approximately 87,200 connections came from a Southeast Asian country targeting state telecom and military networks; approximately 53,100 from a Middle Eastern country, including Starlink-connected addresses in the capital; and approximately 15,000 from a second Southeast Asian country, including government ministry infrastructure. Targets span the Middle East, Southeast Asia, South Asia, and Taiwan, Crypto Briefing reports, with sectors including defence, telecommunications, education, and aviation.

    The cryptocurrency fraud operation runs on an automated pipeline that scrapes keywords, generates thousands of fake download pages using AI, and publishes them across a 44-server content-management fleet and hundreds of lookalike domains impersonating OKX and Binance. AI-generated articles drive traffic to fake crypto exchange sites, while click-fraud bots manipulate search rankings to promote fraudulent pages. The lures extend beyond crypto: sports betting, pirated livestream portals, and private detective scams are also in the mix.

    The financially motivated side of these operations points toward a hack-for-hire dimension. Symantec researchers say they have high confidence attributing Jewelbug’s financially motivated activities to a Chinese company that advertises SEO services. TechTimes further reports that at least one of the group’s operators is linked, via government-issued identity documents, to a registered company in Changsha, Hunan Province, a detail that puts a specific geographic anchor on what has otherwise been a carefully obscured operation.

    What Symantec Has Published

    Symantec has released indicators of compromise related to observed Jewelbug activity alongside a more detailed technical report covering the group’s tooling and tradecraft, its financial operation, and the infrastructure used in attacks. The dual nature of the campaign (state-aligned espionage and commercial cybercrime running on a shared platform) is what Symantec describes as an “industrial-scale cryptocurrency fraud business” sitting alongside the intelligence-gathering work, a combination that suggests the group’s operators are running both for profit and for patrons.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleTrezor ShipMonk data breach exposes 13,000+ customers via Metabase zero-day
    Next Article Apple Threat Notification alerts land again as mercenary spyware campaign hits iPhone users
    Gary Behan

    Software engineer and video game uber-nerd.

    Related Posts

    macOS Screen Sharing exploit actively used to mine Monero, Dutch agency warns

    19/08/2026

    Shell Clop Data Breach Probe Widens as 43 Firms Hit by PTC Flaw

    18/08/2026

    Cameron Curry Brightly Software extortion lands him two years in prison

    18/08/2026

    Apple Threat Notification alerts land again as mercenary spyware campaign hits iPhone users

    18/08/2026

    Trezor ShipMonk data breach exposes 13,000+ customers via Metabase zero-day

    17/08/2026

    WhatsApp Scam Alert Feature Uses On-Device AI to Flag Suspicious Messages

    17/08/2026
    Add A Comment

    Comments are closed.

    Categories
    • Apps & Software
    • Artificial Intelligence
    • Business
    • Computing
    • Education
    • Energy
    • Featured
    • Finance
    • Gadgets
    • Gaming
    • Health and Safety
    • Home
    • Lifestyle
    • Marketing
    • Medical
    • News
    • NFT
    • Opinions
    • Social
    • Technology
    • Travel & Tourism
    Mozbot
    Facebook X (Twitter) Instagram Pinterest
    © 2026 M0ZBOT. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.