logo

Researchers Link 'Jewelbug' Chinese APT to Hack-for-Hire Operations

ID: 85aca07c-6758-5702-a257-6902e7f4211c

STIX ID: report--85aca07c-6758-5702-a257-6902e7f4211c

Feed Name: Infosecurity Magazine (News)

Threat Score
88/100

Date Published: 2026-08-14

Date Updated: 2026-08-14

...
...

Broadcom's Threat Hunter Team attributes a dual-purpose operation to Jewelbug (Ink Dragon/REF770): sophisticated cyber espionage targeting governments across the Middle East, South and Southeast Asia alongside a Chinese-language cryptocurrency fraud scheme. The report highlights shared infrastructure (the XG-Web browser-based C2 and backend), tooling including the Antino Windows backdoor, ClientKing Linux/router implant, a malicious browser extension and abuse of Microsoft Graph and Google Docs for C2 and payload delivery; researchers observed over one million implant check-ins, ~580,000 stolen browser cookies, watering‑hole campaigns on government webmail tenants, and clear operational overlap between espionage and financial fraud.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.