Jewelbug Campaigns Target Middle East and Asia With Espionage and Crypto Fraud

Summary
A WhoisXML API analysis expands on reports of Jewelbug campaigns targeting the Middle East and Asia, examining network indicators and related domains. Researchers found potential victim connections and additional malicious infrastructure.
Key points
- Jewelbug, described as a China-based hackers-for-hire group, reportedly ran cyber-espionage and crypto-fraud campaigns from a shared control panel.
- The cited campaign analysis recorded more than 1 million implant check-ins and 580,000 stolen browser cookies in under three months.
- Researchers examined 27 original network indicators and identified additional domains, IP addresses and related infrastructure; some were confirmed malicious, while others were assessed as suspicious.
- Traffic data showed 670 distinct IP addresses, potentially belonging to victims across 52 autonomous systems, communicating with eight of the group’s IP indicators between March 2 and August 4, 2026.
- One related domain, q-vpn[.]com, was reported as distributing malware since January 27, 2025; browser-update[.]pages[.]dev was identified as a SocGholish-style fake browser update lure.
Article Details
- Attack Vectors
- A confirmed malware host used a SocGholish-style fake browser update lure; the article does not identify the malware as SocGholish.
- The reported infrastructure included malware distribution through cloud-hosted subdomains and suspicious subdomains that appeared to imitate Chrome or Microsoft Azure.
- Security.com reported that Jewelbug ran espionage and crypto-fraud operations from a single control panel. Its victim database recorded more than 1 million implant check-ins and more than 580,000 stolen browser cookies in less than three months.
- Defensive Notes
- The researchers recommend corroborating threat and malicious-infrastructure designations through additional investigation, noting that some may later prove harmless.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | f1ash[.]org[.]cn | Listed domain IOC examined for historical domain-to-IP resolutions. |
| DOMAIN | mailbycloud[.]com | Listed domain IOC examined for historical domain-to-IP resolutions. |
| DOMAIN | q-vpn[.]com | Email-connected domain that the researchers said had been weaponized to distribute malware since 2025-01-27. |
| DOMAIN | wac-azure[.]com | Listed domain IOC examined for historical domain-to-IP resolutions. |
| DOMAIN | wizkidblogger[.]com | Listed domain IOC examined for historical domain-to-IP resolutions. |
| DOMAIN | wps-cn[.]com | Listed domain IOC examined for historical domain-to-IP resolutions. |
| HOSTNAME | browser-update[.]pages[.]dev | Confirmed malware host associated with a fake browser update lure. |
| HOSTNAME | d2nq35tel3ucuo[.]cloudfront[.]net | Cloud-hosted subdomain IOC identified as a malware distributor. |
| HOSTNAME | dns[.]wizkidblogger[.]com | Subdomain IOC in a cluster assessed as possible typosquatting or staging infrastructure. |
| HOSTNAME | eastus2[.]wac-azure[.]com | Subdomain IOC designated suspicious because it could mimic Microsoft Azure. |
| HOSTNAME | fonts[.]chrorne[.]com | Subdomain IOC designated suspicious because it could abuse the Chrome brand. |
| HOSTNAME | fonts[.]tarotfree101[.]top | Subdomain IOC in a cluster assessed as possible typosquatting or staging infrastructure. |
| HOSTNAME | ns1[.]jkskhei[.]com | Subdomain IOC tagged as malicious; researchers said it could imitate a nameserver. |
| HOSTNAME | pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev | Subdomain IOC in a high-risk cloud-platform-abuse cluster; the article does not specify whether this host was active or merely suspicious. |
| HOSTNAME | r6fi2yvqql[.]execute-api[.]ap-southeast-2[.]amazonaws[.]com | Subdomain IOC in a high-risk cloud-platform-abuse cluster; the article does not specify whether this host was active or merely suspicious. |
| HOSTNAME | robot[.]avbliud[.]com | Subdomain IOC in a high-risk cluster sharing operator tradecraft; the article does not specify this host's individual assessment. |
| IPV4 | 103[.]87[.]9[.]62 | Listed IP IOC examined for historical IP-to-domain resolutions. |
| IPV4 | 167[.]71[.]195[.]255 | Listed IP IOC examined for historical IP-to-domain resolutions. |
| IPV4 | 219[.]76[.]254[.]184 | Listed IP IOC examined for historical IP-to-domain resolutions. |
| IPV4 | 43[.]246[.]208[.]179 | Listed IP IOC examined for historical IP-to-domain resolutions. |
| IPV4 | 43[.]246[.]208[.]236 | Listed IP IOC examined for historical IP-to-domain resolutions. |
MITRE ATT&CK
Threat Actors
Vendors
Tools
Bulk IP Geolocation LookupWe then queried the IP IoCs on Bulk IP Geolocation Lookup and discovered that:DNS Chronicle APIWe then queried the domain IoCs on DNS Chronicle API and found out that eight recorded 898 historical domain-to-IP resolutions over time.Domain Info APIWe began by querying them on WHOIS API and filling in gaps with data from Domain Info API.Domain Traffic APIWe also queried the email-connected domains on Domain Traffic API and identified 10 with the highest number of visits.Reverse WHOIS APIWe queried them on Reverse WHOIS API, which led to the discovery of 5,331 distinct email-connected domains after those already dubbed as IoCs were filtered out.Threat Intelligence APIA Domain Research, Whois, DNS, and Threat Intelligence API and Data ProviderWHOIS APIWe began by querying them on WHOIS API and filling in gaps with data from Domain Info API.WHOIS History APIFirst, we queried the domain IoCs on WHOIS History API.WhoisXML API MCP ServerWe extracted unique domains from the subdomain IoCs then determined if any were owned by legitimate companies aided by the WhoisXML API MCP Server.
Countries
ChinaSecurity.com recently published an analysis of a China-based hackers-for-hire group Jewelbug espionage con crypto fraud campaign that trailed their sights on victims across the Middle East and Asia.United StatesThey were geolocated in five countries, two of which—China and the U.S.—were also among the domain IoCs’ registrant countries.