Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side
ID: 81596389-700e-597c-9814-f6933f018cba
STIX ID: report--81596389-700e-597c-9814-f6933f018cba
Feed Name: security.com
Symantec Threat Hunter Team details Jewelbug, a China-based APT/hackers‑for‑hire group operating both espionage campaigns against governments and a for‑profit crypto‑fraud business from the same XG‑Web control panel; tooling includes the Antino Windows backdoor, a malicious “PDF Viewer” browser extension with a native messaging helper, and the ClientKing Rust implant for servers and routers, and the report documents large-scale watering‑hole compromises, over one million implant check‑ins, hundreds of thousands of stolen cookies, and many IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
