Researchers Link 'Jewelbug' Chinese APT to Hack-for-Hire Operations

Broadcom threat intelligence researchers identify Jewelbug as a Chinese APT linked to a high-stakes crypto fraud operation, exploiting vulnerabilities in Microsoft Office and Adobe Acrobat.

Bottom line: Jewelbug may be involved in a sophisticated crypto fraud scheme.

What's happening: Researchers from Broadcom's threat intelligence team analyzed data from the compromised servers of a high-end cryptocurrency exchange, BitMEX, and linked it to Jewelbug, a Chinese APT group known for its advanced malware and spear phishing attacks.

What to do: Security leaders should ensure their teams are aware of the vulnerabilities in Microsoft Office and Adobe Acrobat and apply available patches to prevent exploitation.

Source: Infosecurity Magazine