Dual Threat: Jewelbug’s Cyber Espionage and Cryptocurrency Fraud Operations
Security researchers from Broadcom’s Threat Hunter Team have unearthed alarming revelations about Jewelbug, a threat group that appears to operate at the intersection of state-sponsored cyber espionage and financially motivated cybercrime. This group, closely linked to Chinese-sponsored operations, is not only committing acts of espionage but is also engaging in lucrative cryptocurrency fraud campaigns aimed primarily at Chinese-speaking users.
In a detailed report published on August 13, the threat intelligence team—which integrates expertise from Symantec and Carbon Black—has advanced the understanding of this advanced persistent threat (APT) group. Jewelbug is also known by various aliases including Ink Dragon, Earth Alux, REF770, and CL-STA-0049.
The findings indicate that Jewelbug employs the same technological infrastructure to execute espionage against governmental and military targets in the Middle East, Southeast Asia, and South Asia. Concurrently, it runs an operation targeting cryptocurrency users via deceptive download portals disguised as legitimate exchanges. The report firmly asserts, “The two are not separate ventures that happen to share a name: our investigation revealed they are run by the same small team, on shared infrastructure, from one control panel.”
At the epicenter of these efforts is an operator referred to as ‘ople500,’ identified as the commercial arm of this dual-faceted operation. This individual has adopted the persona of ‘paopaodada’ or ‘bubble boss’ and has gained visibility on Telegram, promoting a “website ranking rental” service. Broadcom associates this persona with a company registered in Changsha, the capital of Hunan province, and they are confident that this individual supplies critical infrastructure and access to support both the espionage and cryptocurrency fraud campaigns.
Targeting Governments and Militaries
Jewelbug’s cyber espionage campaigns have not gone unnoticed. Multiple threat intelligence teams, including Trend Micro’s TrendAI, Palo Alto Networks’ Unit 42, and Check Point Research, have documented the group’s nefarious activities. The threat actors typically exploit vulnerabilities within Internet Information Services (IIS) and SharePoint servers, subsequently deploying web shells and a sophisticated backdoor known as VARGEIT or Squidoor.
Broadcom’s researchers have uncovered that Jewelbug has gained access to numerous governmental organizations across the mentioned regions, identifying over 90 email addresses linked to police and government entities in South Asia alone. They have also discovered a significant victim database, accumulating more than one million implant check-ins and over 580,000 stolen browser cookies within just three months of sustained operations.
In an extensive campaign, Jewelbug successfully deployed a planted script that compromised multiple government webmail tenants all at once in a Middle Eastern nation. This level of sophistication underlies the serious threat posed by this group.
Cryptocurrency Fraud Operations
In tandem with these espionage activities, Jewelbug’s infrastructure has been leveraged for a cryptocurrency fraud operation targeting users in the Chinese-speaking community. Researchers have noted that this dual purpose hints at a broader interest in Taiwan, as decoy documents purporting to be from Taiwanese government organizations were also observed.
Crucially, both the espionage and fraud activities share a common thread: they exploit government communication systems and the service providers hosting them. This convergence allows Jewelbug to maintain long-term access to crucial official correspondence, significantly amplifying the potential ramifications of their activities.
Unified Infrastructure for Espionage and Fraud
At the heart of both operations lies XG-Web, a browser-based command and control (C2) platform that functions as the group’s central management console. The comprehensive Broadcom report outlines how XG-Web is utilized to oversee victim management across both criminal ventures. The same backend database integrates implants, stolen data, and operational metrics for both espionage and cryptocurrency fraud operations.
Among the primary tools associated with this network is Antino, a Windows backdoor that communicates through the Microsoft Graph API, cleverly blending C2 traffic with that of legitimate Microsoft cloud services. The malware is deployed through fake software installers, serving as an entry point for additional nefarious activities.
Moreover, Jewelbug has developed a malicious Chrome and Firefox extension called ‘PDF Viewer’ that is disguised as part of a legitimate Microsoft Edge component. This tool provides expansive access to victims’ browsers, facilitating the theft of credentials, cookies, and browsing data, while also granting command shell capabilities over the compromised hosts.
Alongside Antino, the group utilizes a Linux and router implant known as ClientKing, which can pivot and afford remote shell access while overlapping with the broader XG-Web architecture. Such interconnected operations further illustrate how deeply embedded Jewelbug is in both sectors.
Additionally, the group has been found to exploit Google Docs for malware delivery, using publicly accessible documents to conceal their activities. This method allows them to camouflage malicious operations as regular internet traffic, significantly reducing the likelihood of detection by cybersecurity measures.
In summary, the intersection of cyber espionage and cryptocurrency fraud orchestrated by Jewelbug presents a multi-faceted threat landscape. With shared infrastructure and operations targeting both governmental communications and cryptocurrency users, the group’s capabilities warrant heightened vigilance from both private and public sectors alike.

