Cybersecurity

Jewelbug Group Hacks Email Accounts of 15 Government Entities Alongside Cryptocurrency Scams

Symantec revealed that the Jewelbug group, also known as Earth Alux and REF7707, conducted an espionage campaign targeting government email accounts in the Middle East, alongside extensive activity defrauding cryptocurrency users. The attacks relied on compromising a shared email-hosting platform, planting malware, and stealing cookies and sensitive data.

2026-08-13
4 min read
7 views
فريق تحرير certi.news
Jewelbug Group Hacks Email Accounts of 15 Government Entities Alongside Cryptocurrency Scams

Symantec research revealed that the Jewelbug hacking group compromised email accounts belonging to 15 government entities in a campaign targeting a country in the Middle East, while simultaneously running extensive cryptocurrency-related scams. The combination of espionage and revenue generation through cybercrime indicates that the group may also operate under a hacking-for-hire model, according to researchers.

Jewelbug is also known as Earth Alux and REF7707. It has targeted government and military entities and critical sectors, including defense, telecommunications, education, and aviation. Symantec found that the espionage and financial-fraud operations were managed from a single control panel, revealing links between the infrastructure and operations used in both activities.

Compromising a Shared Government Email Platform

The attackers, whom Symantec describes as a China-based group, obtained write access to a shared hosting platform operated by the government telecommunications company and the National Services Agency. Through access to the email installation used by multiple ministries and agencies, they planted a single script inside the shared template.

The malicious script executed during login and on mailbox pages across more than 15 government domains, opening a WebSocket connection to a command-and-control server. It also stole email cookies and extracted the user’s address to determine whether the user belonged to a targeted government domain.

When the system identified a high-value target, it displayed a fake Adobe Flash update window. Installing this update downloaded the Antino backdoor onto Windows devices, along with browser tools. The group also uses the XG-Web framework for remote access, data theft, campaign management, and victim information.

Software for Stealing Sessions and Data

Jewelbug distributes the Antino malware through malicious HTA files and fake Adobe Flash and Adobe installers, then uses it to download additional payloads. These include a malicious browser extension called PDF Viewer that operates on Chrome and Firefox and can steal cookies and credentials, intercept traffic, inject JavaScript, and provide remote browser functionality.

Symantec traced Antino infections to the group’s infrastructure and then gained visibility into the command-and-control management platform, database, server logs, source code, and operator files. The data showed more than one million records of implant communications with the victim database, more than 580,000 stolen cookies, thousands of credentials, and more than 2,300 extracted emails.

Government Targeting and Automated Fraud

The espionage operations extended to government and military institutions in the Middle East, Southeast Asia, and South Asia. The operational servers recorded approximately 1.1 million geolocation events from nearly 4,300 source IP addresses, including approximately 87,200 connections from a Southeast Asian country targeting government telecommunications and military networks, approximately 53,100 connections from a Middle Eastern country, and approximately 15,000 connections from a second Southeast Asian country.

The financial activity relied on AI-generated articles to attract traffic to fake cryptocurrency-trading websites, along with bots for clicking and manipulating search-result rankings. According to Symantec, the group automatically collects keywords, creates thousands of fake download pages using AI, and then distributes them through a fleet of 44 content-management servers and hundreds of domains resembling OKX and Binance websites.

Other lures included sports-betting websites, pirated live-streaming portals, and scams impersonating private investigators. Symantec said it has high confidence in attributing the financially motivated activities to a Chinese company that advertises search-engine-optimization services.

Multiple Tools for Systems and Infrastructure

Jewelbug also uses the ClientKing tool, developed in Rust, targeting Linux servers, ARM64 devices, and ASUS routers. The tool supports command execution, SOCKS proxy creation, DNS tunneling, and loading kernel modules into memory. The attackers also hosted obfuscated payloads on public Google Documents, helping make the malicious traffic resemble legitimate communications with Google services.

Symantec published indicators of compromise associated with the observed activity, along with a more detailed technical report covering Jewelbug’s tools, methods, financial operations, and the infrastructure used in the attacks.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news