Symantec reveals Jewelbug espionage campaign targeting Asian governments, telecoms, critical infrastructure

Symantec’s Threat Hunter Team identified Jewelbug, a China-based hackers-for-hire group, conducting espionage campaigns against governments and militaries across... The post Symantec reveals Jewelbug espionage campaign targeting Asian governments, telecoms, critical infrastructure appeared first on

Symantec’s Threat Hunter Team identified Jewelbug, a China-based hackers-for-hire group, conducting espionage campaigns against governments and militaries across the Middle East, Southeast Asia and South Asia while operating a parallel cryptocurrency fraud business. The group manages both activities through the same XG-Web control panel, a browser-based remote-access and information-stealing framework. Its tooling includes the Antino Windows backdoor, a malicious ‘PDF Viewer’ browser extension for Chrome and Firefox, and ClientKing, a Linux and router implant that can reach servers and network devices.

The investigation found that Jewelbug collected more than one million implant check-ins, over 580,000 stolen browser cookies, thousands of captured credentials, and more than 2,300 exfiltrated email bodies in less than three months. The group also compromised a shared web hosting platform supporting a Middle Eastern government’s webmail system, establishing watering holes across more than 15 government webmail tenants. Using browser access to reach internal infrastructure, Jewelbug targeted critical infrastructure across Southeast Asia and the Middle East, including state telecom operators, military networks, and government ministries.

Symantec said some ClientKing builds were configured to beacon through the internal corporate proxy of a major U.S. aerospace and industrial manufacturer, extending the group’s activity into infrastructure associated with an industrial organization. 

“A months-long investigation by the Symantec Threat Hunter Team has produced unprecedented visibility into the activities of Jewelbug (aka Earth Alux, REF7707, CL-STA-0049), a China-based APT group that has been breaking into government ministries across Asia and the Middle East while quietly running a cryptocurrency fraud business on the side,” Symantec and Carbon Black Threat Hunter Team researchers wrote in a Thursday blog post. “The two are not separate ventures that happen to share a name: our investigation revealed they are run by the same small team, on shared infrastructure, from one control panel.”

Jewelbug’s commercial arm is affiliated with a registered company in Hunan Province, China. The group has developed five generations of command-and-control (C&C) code and a family of implants spanning browsers, Windows endpoints, Linux servers and network devices, all of it feeding a single database of victims. That toolset serves two missions of espionage attacks against foreign governments and militaries, and for-profit crypto fraud aimed at Chinese-speaking victims.

They added that on the espionage side, campaigns targeted government organizations across the Middle East and Southeast Asia. Other lists targeted more than 90 police and government email addresses in South Asia. “The group’s separate Linux and router implant enables it to extend its reach into network infrastructure, with a couple of builds configured to beacon through the internal corporate proxy of a major U.S. aerospace and industrial manufacturer.” 

The researchers observed that what makes Jewelbug notable is the combination of two missions in one set of hands. “Foreign government and foreign military espionage was run from the same infrastructure, by the same team, as a commodity cryptocurrency fraud business. That pairing is the signature of a hack-for-hire entity that is running for-profit crime on the side.”

They added that the exposure shows the difference between targeting and compromise. Its database did not merely list intended victims: it recorded more than one million implant check-ins, hundreds of thousands of stolen cookies, and intercepted internal network traffic and the harvested mailboxes of senior government officials. Compromising a shared hosting provider and placing a watering-hole on every government tenant on it in one move turned a single intrusion into access across an entire national webmail estate.

Symantec detailed a parallel, financially motivated operation targeted Chinese-speaking cryptocurrency users through fake exchange-download portals. Decoy documents styled after Taiwanese government bodies suggest its interest also extended to Taiwan. The common thread across espionage targets is government communications and the providers that host them, which would give an intelligence customer broad, durable access to official cor

Source: Industrial Cyber