Hackers breach government webmail while running parallel crypto scams

Hackers breach government webmail while running parallel crypto scams

The Jewelbug hacking group conducts espionage operations targeting governments and militaries while also engaging in cryptocurrency scams.

While the threat has targeted government agencies and organizations in critical sectors including defence, telecommunications, education and aviation, its cryptocurrency-related activity suggests they may also be operating as a hacking-for-hire group looking to profit from cybercrime.

In a recent operation, Jewelbug (also known as Earth Alux and REF7707) compromised webmail accounts belonging to 15 government tenants as part of a campaign targeting a Middle Eastern country.

image

Symantec researchers found that the spyware campaign and the cryptocurrency scam were run by the same control panel.

The China-based hacking group gained write access to the shared webmail installation and inserted a malicious script into its shared template. The script then runs on login pages and mailbox views across 15 tenants.

The webmail attack chain
The webmail attack chain
Source: Symantec

Upon execution, the script establishes a WebSocket connection to the attacker’s command-and-control (C2) server, exfiltrates webmail cookies, and extracts the user’s email address to determine whether it belongs to a targeted government domain.

Valuable targets will receive a fake Adobe Flash update prompt that installs the Windows core payload, Antino backdoor, and browser tools.

Besides Antino, the threat also uses the XG-Web remote access and data theft framework to manage campaigns and victim information.

XG-Web panel
The XG-Web panel
Source: Symantec

According to Symantec, Jewelbug delivers Antino via malicious HTA files and fake Adobe Flash/Adobe installers and then uses it to deploy additional payloads.

One of the payloads is a malicious browser extension for Chrome and Firefox called PDF Viewer that steals cookies and credentials, intercepts traffic, injects JavaScript, and remotely exposes browser features.

The capabilities of PDF Viewer
The capabilities of PDF Viewer
Source: Symantec

Symantec traced the Antino infections to Jewelbug’s infrastructure and then gained visibility into the group’s C2 management platform, database, server logs, source code and operator files.

The data shows that the hackers ran a large-scale espionage operation and an “industrial-scale cryptocurrency scam business.”

“Jewelbug’s victim database contains more than one million implanted registration lines, more than 580,000 stolen browser cookies, several thousand captured credentials, and more than 2,300 exfiltrated email bodies,” Symantec researchers noted.

On the espionage side, Jewelbug targeted government and military organizations in the Middle East, Southeast Asia, and South Asia.

“Runtime server logs recorded approximately 1.1 million geolocation events against approximately 4,300 separate source IP addresses: approximately 87,200 connections from a Southeast Asian country (targeting state telecommunications and military networks), approximately 53,100 from a Middle Eastern country (within national carrier coverage, including Starlink-related addresses in the capital), and approximately 15,000 from a second Southeast Asian country (including government department infrastructure) Symantec says.

The researchers explained that the threat gained write access to the webmail installation used by multiple government ministries and agencies after compromising a shared web hosting platform run by the state telecommunications provider and the national service agency.

By injecting a single script tag, the threat ensures that the JavaScript payload opens a WebSocket to C2 whenever a user of one of the nine state domains logs in.

“One campaign covered more than 15 government webmail tenants, with the hook firing on the login page and every mailbox view,” says Symantec.

Cryptocurrency theft operations are supported by AI-generated articles that drive traffic to fake crypto exchange sites and click fraud bots that manipulate search rankings.

Jewelbug's parallel operations
Jewelbug’s parallel operations
Source: Symantec

According to the researchers, the threat relies on an automated attack pipeline that scrapes keywords, generates thousands of fake download pages using AI, and publishes them “within 44 content management servers and hundreds of similar domains” impersonating OKX and Binance. Using click bots, Jewelbug manipulates rankings to promote its scam pages.

The scam also uses other lures: sports betting, pirated live streaming portals and private detective scams.

Symantec researchers have high confidence that they attribute the financially motivated activities of Jewelbug to a Chinese company that advertises SEO services.

Jewelbug also uses a Rust-based implant called “ClientKing” that targets Linux servers, ARM64 devices, and ASUS routers and supports command execution, SOCKS proxies, DNS tunneling, and in-memory kernel module loading.

Hackers have used public Google Docs to host garbled payloads extracted and executed by their implants, helping malicious traffic merge with legitimate Google services.

Symantec publishes indicators of compromise related to observed Jewelbug activity and more detailed technical report describing the tools and skills of the threat, their financial operations and the infrastructure used in attacks.


article image

Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.

The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *