The Jewelbug hacker group has breached government webmail systems in the Middle East while operating a parallel cryptocurrency fraud network. Researchers found that the same infrastructure supported cyber espionage, credential theft and AI-generated scam sites.
Jewelbug compromises shared government webmail
Jewelbug, also tracked as Earth Alux and REF7707, targeted government, military and critical-sector organisations across the Middle East, Southeast Asia and South Asia.
In a recent campaign, the group gained write access to a shared webmail installation used by more than 15 government tenants. The platform reportedly served ministries and agencies through infrastructure operated by a state telecommunications provider and national services agency.
The attackers inserted a malicious script into a shared webmail template. As a result, the code ran whenever users opened the login page or viewed their mailbox.
The script connected to Jewelbug’s command-and-control server through WebSocket. It then stole webmail cookies and checked whether an email address belonged to a targeted government domain.
Selected victims received a fake Adobe Flash update prompt. The prompt delivered Antino, a Windows backdoor, alongside browser-focused malware.
Antino and malicious extensions steal data
Jewelbug uses malicious HTA files and fake Adobe installers to deliver Antino. Once active, the backdoor can install further payloads and give operators greater control over compromised devices.
One of those payloads is a malicious browser extension called PDF Viewer. It targets Chrome and Firefox users and can steal cookies and credentials, intercept browser traffic, inject JavaScript and expose browser functions remotely.
The group also uses the XG-Web remote-access and data-theft framework to manage campaigns and collect victim information.
Researchers who accessed Jewelbug’s infrastructure found evidence of a large operation. Its victim database reportedly contained more than one million implant check-in records, over 580,000 stolen browser cookies, thousands of credentials and more than 2,300 exfiltrated email messages.
Espionage activity targets governments and militaries
The Jewelbug hacker group used the compromised webmail platform to reach multiple government domains. A single injected script allowed its payload to contact the group’s infrastructure whenever users logged in or opened mailbox views.
Server logs showed around 1.1 million geolocation events across roughly 4,300 source IP addresses. The activity included connections linked to state telecommunications and military networks in Southeast Asia, national carrier ranges in the Middle East and government ministry infrastructure in another Southeast Asian country.
Jewelbug also deploys a Rust-based implant named ClientKing. The tool can target Linux servers, ARM64 devices and ASUS routers. Its features include command execution, SOCKS proxying, DNS tunnelling and in-memory kernel module loading.
The attackers used public Google Docs to host obfuscated payloads that their implants retrieved and executed. This technique can make malicious traffic appear more legitimate by blending it with normal Google service activity.
AI-generated crypto scams run in parallel
Alongside espionage, Jewelbug operates a large cryptocurrency fraud business. Researchers found that the group uses AI-generated articles and fake download pages to attract traffic to fraudulent crypto exchange websites.
Its automated pipeline scrapes keywords, creates thousands of pages and publishes them through a network of servers and lookalike domains. Many of the sites impersonate well-known cryptocurrency exchanges.
Click-fraud bots then manipulate search rankings to push the fraudulent pages higher in search results. The campaign also uses sports betting offers, pirated livestream sites and private detective scams as lures.
Researchers attributed Jewelbug’s financially motivated activity with high confidence to a China-based company that promotes SEO services. The overlap between its espionage and fraud systems suggests the group can combine state-aligned targeting with profit-driven cybercrime.


0 responses to “Jewelbug hackers breach government webmail while running crypto fraud”