Jewelbug Campaigns Target Middle East and Asia With Espionage and Crypto Fraud

· Original article ↗

Summary

A WhoisXML API analysis expands on reports of Jewelbug campaigns targeting the Middle East and Asia, examining network indicators and related domains. Researchers found potential victim connections and additional malicious infrastructure.

Key points

  • Jewelbug, described as a China-based hackers-for-hire group, reportedly ran cyber-espionage and crypto-fraud campaigns from a shared control panel.
  • The cited campaign analysis recorded more than 1 million implant check-ins and 580,000 stolen browser cookies in under three months.
  • Researchers examined 27 original network indicators and identified additional domains, IP addresses and related infrastructure; some were confirmed malicious, while others were assessed as suspicious.
  • Traffic data showed 670 distinct IP addresses, potentially belonging to victims across 52 autonomous systems, communicating with eight of the group’s IP indicators between March 2 and August 4, 2026.
  • One related domain, q-vpn[.]com, was reported as distributing malware since January 27, 2025; browser-update[.]pages[.]dev was identified as a SocGholish-style fake browser update lure.

Article Details

Attack Vectors
  • A confirmed malware host used a SocGholish-style fake browser update lure; the article does not identify the malware as SocGholish.
  • The reported infrastructure included malware distribution through cloud-hosted subdomains and suspicious subdomains that appeared to imitate Chrome or Microsoft Azure.
  • Security.com reported that Jewelbug ran espionage and crypto-fraud operations from a single control panel. Its victim database recorded more than 1 million implant check-ins and more than 580,000 stolen browser cookies in less than three months.
Defensive Notes
  • The researchers recommend corroborating threat and malicious-infrastructure designations through additional investigation, noting that some may later prove harmless.

Indicators of compromise

TypeIndicatorContext
DOMAINf1ash[.]org[.]cnListed domain IOC examined for historical domain-to-IP resolutions.
DOMAINmailbycloud[.]comListed domain IOC examined for historical domain-to-IP resolutions.
DOMAINq-vpn[.]comEmail-connected domain that the researchers said had been weaponized to distribute malware since 2025-01-27.
DOMAINwac-azure[.]comListed domain IOC examined for historical domain-to-IP resolutions.
DOMAINwizkidblogger[.]comListed domain IOC examined for historical domain-to-IP resolutions.
DOMAINwps-cn[.]comListed domain IOC examined for historical domain-to-IP resolutions.
HOSTNAMEbrowser-update[.]pages[.]devConfirmed malware host associated with a fake browser update lure.
HOSTNAMEd2nq35tel3ucuo[.]cloudfront[.]netCloud-hosted subdomain IOC identified as a malware distributor.
HOSTNAMEdns[.]wizkidblogger[.]comSubdomain IOC in a cluster assessed as possible typosquatting or staging infrastructure.
HOSTNAMEeastus2[.]wac-azure[.]comSubdomain IOC designated suspicious because it could mimic Microsoft Azure.
HOSTNAMEfonts[.]chrorne[.]comSubdomain IOC designated suspicious because it could abuse the Chrome brand.
HOSTNAMEfonts[.]tarotfree101[.]topSubdomain IOC in a cluster assessed as possible typosquatting or staging infrastructure.
HOSTNAMEns1[.]jkskhei[.]comSubdomain IOC tagged as malicious; researchers said it could imitate a nameserver.
HOSTNAMEpub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]devSubdomain IOC in a high-risk cloud-platform-abuse cluster; the article does not specify whether this host was active or merely suspicious.
HOSTNAMEr6fi2yvqql[.]execute-api[.]ap-southeast-2[.]amazonaws[.]comSubdomain IOC in a high-risk cloud-platform-abuse cluster; the article does not specify whether this host was active or merely suspicious.
HOSTNAMErobot[.]avbliud[.]comSubdomain IOC in a high-risk cluster sharing operator tradecraft; the article does not specify this host's individual assessment.
IPV4103[.]87[.]9[.]62Listed IP IOC examined for historical IP-to-domain resolutions.
IPV4167[.]71[.]195[.]255Listed IP IOC examined for historical IP-to-domain resolutions.
IPV4219[.]76[.]254[.]184Listed IP IOC examined for historical IP-to-domain resolutions.
IPV443[.]246[.]208[.]179Listed IP IOC examined for historical IP-to-domain resolutions.
IPV443[.]246[.]208[.]236Listed IP IOC examined for historical IP-to-domain resolutions.

MITRE ATT&CK

Threat Actors

Vendors

Tools

Countries

Related Articles