logo

'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft

ID: 1ed15a78-a464-5b26-8c91-5186dbe9925d

STIX ID: report--1ed15a78-a464-5b26-8c91-5186dbe9925d

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2026-08-13

Date Updated: 2026-08-13

Author: Nate Nelson

...
...

Symantec research profiles 'Jewelbug', a China-linked mercenary APT that simultaneously performs sophisticated cyber espionage and large-scale cryptocurrency fraud from a shared C2 platform (XG‑Web). Jewelbug uses custom implants (Antino for Windows, ClientKing for Linux) and a malicious browser extension 'PDF Viewer' that steals cookies, session tokens, history, screenshots, and can inject JavaScript or replace crypto addresses; the group manages hundreds of fake exchanges and thousands of phishing sites boosted by click-fraud, has compromised government, military, telecom and major corporate victims across Asia and the Middle East, and amassed hundreds of thousands of stolen browser cookie jars and other credentials, suggesting high sophistication and operational scale likely supporting state-directed or state-tolerated operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.