Jewelbug's multi-target attack campaign: When professional hackers scam crypto using AI
- Kamy Le

- 3 hours ago
- 3 min read
In the world of cybersecurity, we often classify hackers into two distinct groups: cyber spies targeting state secrets on one side, and cybercriminals seeking financial gain on the other. However, a threat actor group known as Jewelbug (believed to be based in China) represents a unique exception.
According to a major investigation by Symantec's Threat Hunter team, Jewelbug is operating a dual campaign: a state-targeted cyber espionage operation alongside an industrial-scale cryptocurrency scam network. Remarkably, both of these contrasting operations are commanded from a single central hub.

Espionage and scams on the same system
Most hacking groups build dedicated infrastructure for each purpose to avoid detection. Jewelbug, however, chose to conserve resources by sharing a single management panel named XG-Web.
From the XG-Web dashboard, the attackers can monitor the progress of intrusions into government ministries and military entities across the Middle East, South Asia, and Southeast Asia, while simultaneously tracking their daily "revenue" from scamming cryptocurrency investors.
Statistical data demonstrates the group's alarming reach: Jewelbug's infrastructure recorded over 1 million connections from victim devices, harvesting 580,000 browser cookies and thousands of critical login credentials in less than three months.
Poisoned by seemingly trusted email platforms
One of Jewelbug's largest espionage campaigns targeted the email system of 15 government agencies in a Middle Eastern nation.
Rather than manually attacking each department, the threat actors targeted the country's shared webmail server provider. After acquiring administrative access, they covertly injected a small malicious script into the central login page. Consequently, any employee opening the webmail interface, regardless of department, landed in their crosshairs.
Upon victim login, the system automatically analyzed whether the account was high-value. If the target met their criteria, a prompt popped up requesting an "Adobe Flash software update" or presenting political and military documents as lures. A single click to download allowed a backdoor spyware named Antino to deeply compromise the machine, granting the hackers full control.
PDF Viewer extension – The hidden thief on the browser
Alongside the Antino backdoor, Jewelbug's most dangerous weapon is a malicious browser extension designed for both Chrome and Firefox.
Masquerading as a document reading utility named "PDF Viewer," the extension demands maximum permissions once inadvertently installed: reading cookies, tracking browsing history, intercepting network traffic, and executing background scripts autonomously.
Imagine everything typed into the browser—from email passwords to banking details—being captured by "PDF Viewer" and exfiltrated to the attackers' server in real time. The threat actor even integrated a feature capable of hijacking cryptocurrency wallet addresses: when a user copies their wallet address to receive funds, the malware covertly overwrites it with the hacker's address upon pasting.

Cryptocurrency scams fueled by AI
To maximize financial returns, Jewelbug runs a highly sophisticated Search Engine Optimization (SEO) manipulation campaign targeting Chinese-speaking users.
Rather than manually writing fraudulent content, they utilize AI to continuously generate thousands of fake articles and malicious download pages. These websites are crafted to impersonate well-known cryptocurrency exchanges such as Binance and OKX.
By employing automated bot software to continuously generate artificial click traffic, Jewelbug manipulates search engines to rank these fake sites at the top of search results. Users seeking to download official exchange apps risk losing their entire digital asset portfolio if they inadvertently click these deceptive links.
To cover their tracks, the group hosts malicious code snippets on public Google Docs files. Because Google is a legitimate service, standard antivirus software finds it difficult to detect these malicious data streams.
Jewelbug's campaign serves as a stark warning about the evolving complexity of modern cyber threats. As the line between financially motivated thieves and nation-state spies grows increasingly blurred, the sophistication of cyber attacks will continue to rise.
Reference: Symantec by Broadcom











Comments