Jewelbug APT Ran Government Espionage and Crypto Fraud from Shared Infrastructure

· Original article ↗

Summary

Symantec researchers detail Jewelbug’s espionage and crypto-fraud operations, including its browser and endpoint implants, government webmail watering-hole campaign, and database records of more than one million implant check-ins.

Key points

  • Symantec’s investigation links Jewelbug, a China-based group, to government and military espionage across Asia and the Middle East and a parallel cryptocurrency-fraud operation using shared infrastructure and the XG-Web control panel.
  • A malicious “PDF Viewer” extension for Chrome and Firefox stole credentials, cookies, browsing data, and other information; a native-messaging helper extended access from the browser to the Windows host.
  • The group used Antino, a Windows backdoor that communicates through Microsoft Graph, and ClientKing, a Rust implant targeting Linux servers and network devices, including ASUS routers.
  • In a major campaign, Jewelbug compromised a shared government webmail hosting platform and planted a watering-hole script across more than 15 government tenants, delivering Antino through a fake Adobe Flash update lure.
  • The group’s database recorded more than one million implant check-ins, over 580,000 stolen browser cookies, several thousand credentials, and more than 2,300 exfiltrated email bodies.
  • The fraud operation used fake cryptocurrency exchange download portals and look-alike domains; the article says a clipboard address-swapping feature was present but no replacement rules were deployed during the observed period.

Article Details

Attack Vectors
  • Jewelbug compromised a shared government webmail installation and inserted one script tag into its common template, planting a watering hole across more than 15 tenants.
  • The injected script collected webmail cookies and identified users before presenting selected Windows users with a fake Adobe Flash update that downloaded the Antino backdoor.
  • Antino sideloaded a malicious “PDF Viewer” browser extension and installed a native-messaging helper that let operators run host commands through the Windows command interpreter.
  • The extension hooked login forms, stole cookies and new session tokens, and collected browser data. Its cryptocurrency-address clipboard replacement module was active on victims, but no replacement rules were deployed during the observed period.
  • XG-Web campaigns placed obfuscated payloads in public Google Documents for implants to fetch and execute.
  • ClientKing builds targeted Linux servers and network devices, with capabilities including a custom DNS tunnel, an interactive shell and SOCKS pivoting.
  • The cryptocurrency-fraud operation used fake exchange-download pages, look-alike domains, SEO poisoning and click-fraud bots.
Defensive Notes
  • The article directs readers to the Symantec Protection Bulletin for current protection updates and says Symantec Endpoint products will detect and block malicious IOC files when those files are available to Symantec.
  • The reported watering hole sat in a shared webmail template, so examining only individual government tenants would not capture the full reported scope.
  • The investigation identified malicious browser-extension permissions and native-messaging registration as relevant artifacts; the reported helper used the name com.microsoft.runedge.

Indicators of compromise

TypeIndicatorContext
DOMAINbrowser-update[.]pages[.]devDomain listed among the operation's network indicators.
DOMAINmailbycloud[.]comDomain listed among the operation's network indicators.
DOMAINmicrosoft-flash[.]comGroup-controlled domain used to distribute a fake Adobe installer carrying Antino.
HOSTNAMEdns[.]wizkidblogger[.]comHost listed among the operation's network indicators.
HOSTNAMEeastus2[.]wac-azure[.]comHost listed among the operation's network indicators.
HOSTNAMEfonts[.]chrorne[.]comHost serving the injected government-webmail watering-hole script.
HOSTNAMEfonts[.]tarotfree101[.]topHost listed among the operation's network indicators.
HOSTNAMEns1[.]jkskhei[.]comHost listed among the operation's network indicators.
HOSTNAMEr6fi2yvqql[.]execute-api[.]ap-southeast-2[.]amazonaws[.]comSpecific cloud-service host listed among the operation's network indicators.
HOSTNAMErobot[.]avbliud[.]comHost listed among the operation's network indicators.
HOSTNAMEwww[.]f1ash[.]org[.]cnHost listed among the operation's network indicators and used for an installer download.
HOSTNAMEwww[.]jkskhei[.]comHost listed among the operation's network indicators.
HOSTNAMEwww[.]wps-cn[.]comHost listed among the operation's network indicators.
IPV4103[.]87[.]9[.]62IP address listed among the operation's network indicators.
IPV4129[.]212[.]237[.]224IP address listed among the operation's network indicators.
IPV4152[.]42[.]174[.]151IP address listed among the operation's network indicators.
IPV4167[.]71[.]195[.]255IP address listed among the operation's network indicators.
IPV4219[.]76[.]254[.]184IP address listed among the operation's network indicators.
IPV438[.]12[.]1[.]47IP address listed among the operation's network indicators.
IPV443[.]246[.]208[.]179IP address listed among the operation's network indicators.
IPV443[.]246[.]208[.]236IP address listed among the operation's network indicators.
IPV447[.]250[.]208[.]35IP address listed among the operation's network indicators.
IPV447[.]84[.]37[.]113IP address listed among the operation's network indicators.
IPV447[.]84[.]51[.]173IP address listed among the operation's network indicators.
IPV447[.]87[.]71[.]167IP address listed among the operation's network indicators.
SHA25601b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31aHTA downloader listed as a file indicator.
SHA25609ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cffAntino backdoor sample.
SHA2560c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bdAntino sample from microsoft-flash[.]com that connected to the Microsoft Graph API.
SHA256153d077bcb58e00f5746573cba25f6b0788b809bf7b2a52fca0dc22d3bb5c94eAntino-related sample observed on an infected Middle Eastern host.
SHA256297413a3e49e7353bf484a3eb15ec647de729211059df8fc68678d2378b6f561Antino-related sample observed on an infected Middle Eastern host.
SHA25630f5122cc199b9c2e524503b343a9ee13a6f9773dcbc1df82c8b25ad20bca61dAntino-related sample observed on an infected Middle Eastern host.
SHA256430f12970f8d58f12edccee9019a1aa90fa232c961449bdcc69c8d348a52cf55Antino-related sample observed on an infected Middle Eastern host.
SHA2565ccdf53881f6c758af8d94fe67066af209b4bc0a3cb80b6a4c724fad86eb97efAntino-related sample observed on an infected Middle Eastern host.
SHA2565edb8d1023b8babf302871b68fa2b26d5ca57633f64951922998e8f1d6c8f7acAntino-related sample observed on an infected Middle Eastern host.
SHA2566d5fe6b6a34eeb470798b970b70f41a07ccf59b22f49ad9b3dfff7aa3256f3c2Antino-related sample observed on an infected Middle Eastern host.
SHA25697c3a6be1711c5340d8806e4a54f7297f3f763d0aa4240b667f1e4e1f98f2aadAntino-related sample observed on an infected Middle Eastern host.
SHA2569b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3Adobe_installer (1).exe listed as a file indicator.
SHA256ac3d453d3c9b0310ebb8a67cef35e2ac954d4acdf70cf497fe43a02c7a510813Antino-related sample observed on an infected Middle Eastern host.
SHA256b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85eFile indicator for flashcenter_pp_ax_install_en.exe, a fake-installer filename associated with Antino delivery.
SHA256c11714f9fe2df1ca906585c81498cd77f5ec05b132aab73fa3a71d71d71e42ccAntino backdoor sample.
SHA256e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530slc.dll listed as a file indicator.
SHA256e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcfHTA lure document listed as a file indicator.
SHA256e782a6d4919f194d41e524ebd6df5894197043cf772fcf60455127b246f302c0Antino-related sample observed on an infected Middle Eastern host.
SHA256e7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bbVb0c44dfslc.dll.wxb listed as a file indicator.
SHA256e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34HTA lure document listed as a file indicator.
SHA256ea893abf20b00d9bfc042a88fbf7b4bd42e68ce07c116d3e3b002e5b4a853877Antino-related sample observed on an infected Middle Eastern host.
SHA256ed96e7f1085a50251eb8967ac53777272a617831084f0edad8a769c583a18869Antino-related sample observed on an infected Middle Eastern host.
SHA256f1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8TEST.hta listed as a file indicator.
URLhxxp[:]//d2nq35tel3ucuo[.]cloudfront[.]net/LtVGUSsyUTDA[.]logSpecific cloud-hosted resource listed among the operation's network indicators.
URLhxxps[:]//fonts[.]chrorne[.]com/dist/js/12[.]qgfvjzvs[.]chunk[.]jsInjected watering-hole script on compromised government webmail tenants.
URLhxxps[:]//microsoft-flash[.]com/download/Adobeinstall[.]exeGroup-controlled download URL for the Antino backdoor.
URLhxxps[:]//microsoft-flash[.]com/download/flashcenter_pp_ax_install_en[.]exeDownload URL for a fake installer associated with Antino delivery.
URLhxxps[:]//pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/hjgzBskgslc[.]dll[.]iwqSpecific cloud-hosted DLL-related resource listed among the operation's network indicators.
URLhxxps[:]//www[.]f1ash[.]org[.]cn/flashcenter_pp_ax_install_cn[.]exeFake-installer download URL listed among the operation's network indicators.

MITRE ATT&CK

T1014 · RootkitA companion toolkit for ClientKing included a kernel-module rootkit.T1027 · Obfuscated Files or InformationThe framework served freshly obfuscated payloads XOR-encoded with random keys so successive downloads differed.T1036 · MasqueradingThe malicious browser extension posed as “PDF Viewer”, its helper posed as an Edge component, and Antino was delivered through fake Adobe installers.T1059.003 · Windows Command ShellThe extension's native-messaging helper ran operator commands through the Windows command interpreter.T1059.007 · JavaScriptOperators could direct the “PDF Viewer” extension to inject and execute arbitrary JavaScript on pages visited by victims.T1071.001 · Web ProtocolsAntino used the Microsoft Graph API as its command-and-control channel, and the injected webmail script connected to its C&C over WebSocket.T1071.004 · DNSClientKing supported a custom DNS tunnel as one of its C&C transports.T1090 · ProxyClientKing supported SOCKS pivoting, and some builds were configured to beacon through a manufacturer's internal corporate proxy.T1113 · Screen CaptureThe malicious extension could capture screenshots from victims' browsers.T1115 · Clipboard DataThe malicious extension captured clipboard contents; an address-swapping module was present, although no replacement rules were deployed during the observed period.T1176.001 · Browser ExtensionsAntino sideloaded the malicious “PDF Viewer” extension, which gave operators access to browser APIs and victim browsing data.T1189 · Drive-by CompromiseJewelbug planted an injected script in a shared government webmail template, exposing users across more than 15 tenants to a watering hole.T1204.002 · Malicious FileA fake Adobe Flash update prompt induced targeted webmail users to download and run an executable that installed Antino.T1539 · Steal Web Session CookieThe extension and injected webmail script exfiltrated browser or page cookies; the extension also monitored changes to obtain new session tokens.T1556.003 · Pluggable Authentication ModulesA malicious authentication module in the ClientKing companion toolkit hooked su and sudo to steal credentials.

Threat Actors

Malware

Vendors

Products

Tools

Countries

Industries

Related Articles