Jewelbug APT Ran Government Espionage and Crypto Fraud from Shared Infrastructure

Summary
Symantec researchers detail Jewelbug’s espionage and crypto-fraud operations, including its browser and endpoint implants, government webmail watering-hole campaign, and database records of more than one million implant check-ins.
Key points
- Symantec’s investigation links Jewelbug, a China-based group, to government and military espionage across Asia and the Middle East and a parallel cryptocurrency-fraud operation using shared infrastructure and the XG-Web control panel.
- A malicious “PDF Viewer” extension for Chrome and Firefox stole credentials, cookies, browsing data, and other information; a native-messaging helper extended access from the browser to the Windows host.
- The group used Antino, a Windows backdoor that communicates through Microsoft Graph, and ClientKing, a Rust implant targeting Linux servers and network devices, including ASUS routers.
- In a major campaign, Jewelbug compromised a shared government webmail hosting platform and planted a watering-hole script across more than 15 government tenants, delivering Antino through a fake Adobe Flash update lure.
- The group’s database recorded more than one million implant check-ins, over 580,000 stolen browser cookies, several thousand credentials, and more than 2,300 exfiltrated email bodies.
- The fraud operation used fake cryptocurrency exchange download portals and look-alike domains; the article says a clipboard address-swapping feature was present but no replacement rules were deployed during the observed period.
Article Details
- Attack Vectors
- Jewelbug compromised a shared government webmail installation and inserted one script tag into its common template, planting a watering hole across more than 15 tenants.
- The injected script collected webmail cookies and identified users before presenting selected Windows users with a fake Adobe Flash update that downloaded the Antino backdoor.
- Antino sideloaded a malicious “PDF Viewer” browser extension and installed a native-messaging helper that let operators run host commands through the Windows command interpreter.
- The extension hooked login forms, stole cookies and new session tokens, and collected browser data. Its cryptocurrency-address clipboard replacement module was active on victims, but no replacement rules were deployed during the observed period.
- XG-Web campaigns placed obfuscated payloads in public Google Documents for implants to fetch and execute.
- ClientKing builds targeted Linux servers and network devices, with capabilities including a custom DNS tunnel, an interactive shell and SOCKS pivoting.
- The cryptocurrency-fraud operation used fake exchange-download pages, look-alike domains, SEO poisoning and click-fraud bots.
- Defensive Notes
- The article directs readers to the Symantec Protection Bulletin for current protection updates and says Symantec Endpoint products will detect and block malicious IOC files when those files are available to Symantec.
- The reported watering hole sat in a shared webmail template, so examining only individual government tenants would not capture the full reported scope.
- The investigation identified malicious browser-extension permissions and native-messaging registration as relevant artifacts; the reported helper used the name com.microsoft.runedge.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | browser-update[.]pages[.]dev | Domain listed among the operation's network indicators. |
| DOMAIN | mailbycloud[.]com | Domain listed among the operation's network indicators. |
| DOMAIN | microsoft-flash[.]com | Group-controlled domain used to distribute a fake Adobe installer carrying Antino. |
| HOSTNAME | dns[.]wizkidblogger[.]com | Host listed among the operation's network indicators. |
| HOSTNAME | eastus2[.]wac-azure[.]com | Host listed among the operation's network indicators. |
| HOSTNAME | fonts[.]chrorne[.]com | Host serving the injected government-webmail watering-hole script. |
| HOSTNAME | fonts[.]tarotfree101[.]top | Host listed among the operation's network indicators. |
| HOSTNAME | ns1[.]jkskhei[.]com | Host listed among the operation's network indicators. |
| HOSTNAME | r6fi2yvqql[.]execute-api[.]ap-southeast-2[.]amazonaws[.]com | Specific cloud-service host listed among the operation's network indicators. |
| HOSTNAME | robot[.]avbliud[.]com | Host listed among the operation's network indicators. |
| HOSTNAME | www[.]f1ash[.]org[.]cn | Host listed among the operation's network indicators and used for an installer download. |
| HOSTNAME | www[.]jkskhei[.]com | Host listed among the operation's network indicators. |
| HOSTNAME | www[.]wps-cn[.]com | Host listed among the operation's network indicators. |
| IPV4 | 103[.]87[.]9[.]62 | IP address listed among the operation's network indicators. |
| IPV4 | 129[.]212[.]237[.]224 | IP address listed among the operation's network indicators. |
| IPV4 | 152[.]42[.]174[.]151 | IP address listed among the operation's network indicators. |
| IPV4 | 167[.]71[.]195[.]255 | IP address listed among the operation's network indicators. |
| IPV4 | 219[.]76[.]254[.]184 | IP address listed among the operation's network indicators. |
| IPV4 | 38[.]12[.]1[.]47 | IP address listed among the operation's network indicators. |
| IPV4 | 43[.]246[.]208[.]179 | IP address listed among the operation's network indicators. |
| IPV4 | 43[.]246[.]208[.]236 | IP address listed among the operation's network indicators. |
| IPV4 | 47[.]250[.]208[.]35 | IP address listed among the operation's network indicators. |
| IPV4 | 47[.]84[.]37[.]113 | IP address listed among the operation's network indicators. |
| IPV4 | 47[.]84[.]51[.]173 | IP address listed among the operation's network indicators. |
| IPV4 | 47[.]87[.]71[.]167 | IP address listed among the operation's network indicators. |
| SHA256 | 01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a | HTA downloader listed as a file indicator. |
| SHA256 | 09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff | Antino backdoor sample. |
| SHA256 | 0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd | Antino sample from microsoft-flash[.]com that connected to the Microsoft Graph API. |
| SHA256 | 153d077bcb58e00f5746573cba25f6b0788b809bf7b2a52fca0dc22d3bb5c94e | Antino-related sample observed on an infected Middle Eastern host. |
| SHA256 | 297413a3e49e7353bf484a3eb15ec647de729211059df8fc68678d2378b6f561 | Antino-related sample observed on an infected Middle Eastern host. |
| SHA256 | 30f5122cc199b9c2e524503b343a9ee13a6f9773dcbc1df82c8b25ad20bca61d | Antino-related sample observed on an infected Middle Eastern host. |
| SHA256 | 430f12970f8d58f12edccee9019a1aa90fa232c961449bdcc69c8d348a52cf55 | Antino-related sample observed on an infected Middle Eastern host. |
| SHA256 | 5ccdf53881f6c758af8d94fe67066af209b4bc0a3cb80b6a4c724fad86eb97ef | Antino-related sample observed on an infected Middle Eastern host. |
| SHA256 | 5edb8d1023b8babf302871b68fa2b26d5ca57633f64951922998e8f1d6c8f7ac | Antino-related sample observed on an infected Middle Eastern host. |
| SHA256 | 6d5fe6b6a34eeb470798b970b70f41a07ccf59b22f49ad9b3dfff7aa3256f3c2 | Antino-related sample observed on an infected Middle Eastern host. |
| SHA256 | 97c3a6be1711c5340d8806e4a54f7297f3f763d0aa4240b667f1e4e1f98f2aad | Antino-related sample observed on an infected Middle Eastern host. |
| SHA256 | 9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3 | Adobe_installer (1).exe listed as a file indicator. |
| SHA256 | ac3d453d3c9b0310ebb8a67cef35e2ac954d4acdf70cf497fe43a02c7a510813 | Antino-related sample observed on an infected Middle Eastern host. |
| SHA256 | b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e | File indicator for flashcenter_pp_ax_install_en.exe, a fake-installer filename associated with Antino delivery. |
| SHA256 | c11714f9fe2df1ca906585c81498cd77f5ec05b132aab73fa3a71d71d71e42cc | Antino backdoor sample. |
| SHA256 | e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530 | slc.dll listed as a file indicator. |
| SHA256 | e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf | HTA lure document listed as a file indicator. |
| SHA256 | e782a6d4919f194d41e524ebd6df5894197043cf772fcf60455127b246f302c0 | Antino-related sample observed on an infected Middle Eastern host. |
| SHA256 | e7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb | Vb0c44dfslc.dll.wxb listed as a file indicator. |
| SHA256 | e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34 | HTA lure document listed as a file indicator. |
| SHA256 | ea893abf20b00d9bfc042a88fbf7b4bd42e68ce07c116d3e3b002e5b4a853877 | Antino-related sample observed on an infected Middle Eastern host. |
| SHA256 | ed96e7f1085a50251eb8967ac53777272a617831084f0edad8a769c583a18869 | Antino-related sample observed on an infected Middle Eastern host. |
| SHA256 | f1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8 | TEST.hta listed as a file indicator. |
| URL | hxxp[:]//d2nq35tel3ucuo[.]cloudfront[.]net/LtVGUSsyUTDA[.]log | Specific cloud-hosted resource listed among the operation's network indicators. |
| URL | hxxps[:]//fonts[.]chrorne[.]com/dist/js/12[.]qgfvjzvs[.]chunk[.]js | Injected watering-hole script on compromised government webmail tenants. |
| URL | hxxps[:]//microsoft-flash[.]com/download/Adobeinstall[.]exe | Group-controlled download URL for the Antino backdoor. |
| URL | hxxps[:]//microsoft-flash[.]com/download/flashcenter_pp_ax_install_en[.]exe | Download URL for a fake installer associated with Antino delivery. |
| URL | hxxps[:]//pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/hjgzBskgslc[.]dll[.]iwq | Specific cloud-hosted DLL-related resource listed among the operation's network indicators. |
| URL | hxxps[:]//www[.]f1ash[.]org[.]cn/flashcenter_pp_ax_install_cn[.]exe | Fake-installer download URL listed among the operation's network indicators. |
MITRE ATT&CK
T1014 · RootkitA companion toolkit for ClientKing included a kernel-module rootkit.T1027 · Obfuscated Files or InformationThe framework served freshly obfuscated payloads XOR-encoded with random keys so successive downloads differed.T1036 · MasqueradingThe malicious browser extension posed as “PDF Viewer”, its helper posed as an Edge component, and Antino was delivered through fake Adobe installers.T1059.003 · Windows Command ShellThe extension's native-messaging helper ran operator commands through the Windows command interpreter.T1059.007 · JavaScriptOperators could direct the “PDF Viewer” extension to inject and execute arbitrary JavaScript on pages visited by victims.T1071.001 · Web ProtocolsAntino used the Microsoft Graph API as its command-and-control channel, and the injected webmail script connected to its C&C over WebSocket.T1071.004 · DNSClientKing supported a custom DNS tunnel as one of its C&C transports.T1090 · ProxyClientKing supported SOCKS pivoting, and some builds were configured to beacon through a manufacturer's internal corporate proxy.T1113 · Screen CaptureThe malicious extension could capture screenshots from victims' browsers.T1115 · Clipboard DataThe malicious extension captured clipboard contents; an address-swapping module was present, although no replacement rules were deployed during the observed period.T1176.001 · Browser ExtensionsAntino sideloaded the malicious “PDF Viewer” extension, which gave operators access to browser APIs and victim browsing data.T1189 · Drive-by CompromiseJewelbug planted an injected script in a shared government webmail template, exposing users across more than 15 tenants to a watering hole.T1204.002 · Malicious FileA fake Adobe Flash update prompt induced targeted webmail users to download and run an executable that installed Antino.T1539 · Steal Web Session CookieThe extension and injected webmail script exfiltrated browser or page cookies; the extension also monitored changes to obtain new session tokens.T1556.003 · Pluggable Authentication ModulesA malicious authentication module in the ClientKing companion toolkit hooked su and sudo to steal credentials.
Threat Actors
JewelbugChina-based hackers-for-hire group conducting government and military espionage alongside cryptocurrency fraud; the article identifies Earth Alux, REF7707 and CL-STA-0049 as alternate names.paopaodadaHandle the researchers attribute with high confidence to the individual running the cryptocurrency-fraud and SEO arm. The precise relationship between this individual and the espionage operators is not fully established.
Malware
AntinoJewelbug’s main implant is the Antino backdoor. It also operates a malicious Chrome and Firefox extension posing as an application called “PDF Viewer”, paired with a helper disguised as a Microsoft Edge component thatClientKingClientKing, a Linux and router implantPDF Viewerbackdoor. It also operates a malicious Chrome and Firefox extension posing as an application called “PDF Viewer”, paired with a helper disguised as a Microsoft Edge component that gave operators a command shell on
Vendors
GoogleCommand-and-control through Google DocsMicrosoftand Firefox extension posing as an application called “PDF Viewer”, paired with a helper disguised as a Microsoft Edge component that gave operators a command shell on the host.SymantecA months-long investigation by the Symantec Threat Hunter Team has produced unprecedented visibility into the activities of Jewelbug (aka Earth Alux, REF7707, CL-STA-0049), a China-based APT group that has been breaking
Products
Google ChromeJewelbug’s main implant is the Antino backdoor. It also operates a malicious Chrome and Firefox extension posing as an application called “PDF Viewer”, paired with a helper disguised as a Microsoft Edge component thatGoogle DocsCommand-and-control through Google DocsLinuxof command-and-control (C&C) code and a family of implants spanning browsers, Windows endpoints, Linux servers and network devices, all of it feeding a single database of victims. That toolset serves twoMicrosoft Graph APIOnce running, Antino uses the Microsoft Graph API as its C&C channel, hiding its traffic inside legitimate Microsoft cloud services. It is a shared tool used across the group's campaigns, recovered from infected hostsMicrosoft Windowsdeveloped five generations of command-and-control (C&C) code and a family of implants spanning browsers, Windows endpoints, Linux servers and network devices, all of it feeding a single database of victims. ThatMozilla FirefoxJewelbug’s main implant is the Antino backdoor. It also operates a malicious Chrome and Firefox extension posing as an application called “PDF Viewer”, paired with a helper disguised as a Microsoft Edge component thatSymantec EndpointIf an IOC is malicious and the file is available to us, Symantec Endpoint products will detect and block that file.
Tools
VirusTotalA scheduled job checked the group's own C&C domains against VirusTotal every 12 hours so operators could rotate away from anything that had been flagged.XG-WebBoth missions are administered from a single control panel, XG-Web, a browser-centric remote-access and information-stealing framework that turns a victim’s browser into a full remote-control channel and reaches from
Countries
ChinaChina-based hackers-for-hire group is breaking into government ministries across the Middle East and Asia from the same control panel it uses to run an industrial-scale cryptocurrency fraud business.Taiwanportals. Decoy documents styled after Taiwanese government bodies suggest its interest also extended to Taiwan. The common thread across espionage targets is government communications and the providers that hostUnited States
Industries
Aerospaceof active operations. One set of implants was configured to utilize the internal proxy of a major U.S. aerospace and industrial manufacturer.CryptocurrencyChina-based hackers-for-hire group is breaking into government ministries across the Middle East and Asia from the same control panel it uses to run an industrial-scale cryptocurrency fraud business.GovernmentChina-based hackers-for-hire group is breaking into government ministries across the Middle East and Asia from the same control panel it uses to run an industrial-scale cryptocurrency fraud business.Militaryaddresses: approximately 87,200 connections from a Southeast Asian country (targeting state telecom and military networks), approximately 53,100 from a Middle Eastern country (across the national carrier’s ranges,Telecommunicationseach ministry separately, Jewelbug compromised the shared web-hosting platform run by the state telecommunications provider and national network-services agency, obtaining write access to the common webmail