Jewelbug Expands Cyber Espionage And Cryptocurrency Fraud Through XG Web Platform

Published:

The China linked threat actor known as Jewelbug has been identified carrying out large scale cyber espionage operations targeting governments and military organizations while simultaneously operating a financially motivated cryptocurrency fraud campaign. According to researchers from Broadcom Symantec and Carbon Black Threat Hunter Team, both operations are managed through a single browser centric remote access and information stealing framework called XG Web. The platform transforms a victim browser into a remote control channel that enables attackers to access compromised systems and extend their reach into internal networks. Researchers said the same infrastructure supports both intelligence gathering against government and military targets and cryptocurrency scams aimed primarily at Chinese speaking users. The findings highlight how the threat actor combines state focused cyber operations with profit driven criminal activities using a shared command and control environment.

Broadcom researchers assess Jewelbug to be a China based hackers for hire group conducting parallel operations across multiple regions. Its espionage activity has targeted governments and military organizations in the Middle East, Southeast Asia, and South Asia, while its financial operation focuses on cryptocurrency users through fake exchange download portals. The group has reportedly developed five generations of command and control infrastructure together with a broad family of malware capable of infecting web browsers, Windows systems, Linux servers, and network devices. All compromised systems feed information into a centralized victim database. Researchers also linked at least one operator to a registered company in Hunan Province and noted that the threat actor overlaps with threat clusters tracked as CL STA 0049 by Palo Alto Networks Unit 42, Earth Alux by Trend Micro, and REF7707 by Elastic Security Labs. During a months long investigation, Symantec uncovered campaign records showing espionage operations against government organizations across the Middle East and Southeast Asia, as well as more than 90 police and government email addresses in South Asia. The investigation also found Linux and router implants designed to expand access into network infrastructure, including versions configured to communicate through the internal corporate proxy of a major United States aerospace and industrial manufacturer. Researchers further observed decoy documents impersonating Taiwanese government entities, suggesting that Taiwan may also have been among the intended targets.

At the center of these operations is XG Web, a browser focused remote access and information theft platform built using React, Node.js, and a MySQL database. Although described by its developers as a penetration testing platform, researchers found that it actively checks its own command and control infrastructure against VirusTotal every 12 hours to rotate servers and reduce the risk of detection. The platform also uses publicly accessible Google Docs to store obfuscated payloads that are retrieved and executed by compromised systems. These payloads are encoded with randomly generated XOR keys to ensure every version appears different, while command and control hostnames imitate legitimate services such as Google Fonts. The primary malware used during the campaigns is a malicious browser extension called PDF Viewer that works on both Google Chrome and Mozilla Firefox. Once installed, the extension requests extensive permissions that allow it to access cookies, browsing history, login forms, downloads, bookmarks, screenshots, clipboard contents, and web traffic while executing arbitrary JavaScript on visited websites. The extension also communicates with a Windows helper application registered under the misleading name com.microsoft.runedge, enabling attackers to execute system commands outside the browser environment. Researchers identified additional malware including Antino, a Windows backdoor delivered through malicious HTML Application downloaders or fake Adobe installers that uses Microsoft Graph API for command and control communications, and ClientKing, a Rust based implant targeting Linux servers and routers that supports multiple communication channels, DNS tunneling, interactive shell access, SOCKS pivoting, kernel module loading, and credential theft through modified authentication components.

Researchers described one campaign as the largest espionage operation conducted by Jewelbug after the group compromised a web hosting provider to inject malicious JavaScript into a commonly used government webmail platform serving multiple ministries in a Middle Eastern country. The injected code captured browser cookies through WebSocket communications and delivered a second stage payload only when specific government email addresses, uncompromised accounts, and Windows systems were detected. Victims who accepted a fake Adobe Flash update downloaded the Antino malware, which also installed the PDF Viewer extension and modified the Windows Registry to ensure persistent execution. According to Broadcom, the campaign generated more than one million implant check in records, collected over 580,000 browser cookies, captured thousands of credentials, and exfiltrated at least 2,300 email messages. Runtime server logs also recorded around 1.1 million geolocation events involving approximately 4,300 unique source IP addresses, including about 87,200 connections from a Southeast Asian country, approximately 53,100 from a Middle Eastern country, and roughly 15,000 from another Southeast Asian nation. Researchers also found that the financial operation is operated through a registered Chinese company advertising search engine optimization services on Telegram while allegedly running an SEO poisoning campaign that uses AI generated websites impersonating OKX and Binance. These fake websites distribute trojanized desktop applications or the malicious PDF Viewer browser extension to steal sensitive user information. Broadcom Symantec and Carbon Black concluded that Jewelbug demonstrates how the boundaries between nation state cyber operations and financially motivated cybercrime continue to overlap, with the same infrastructure and operators supporting both government espionage and cryptocurrency fraud. 

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Related articles

spot_img