Threat reportThreat IntelligenceTL-2026-2002

Jewelbug APT Runs Espionage and Crypto Fraud Operations Side by Side

highACTIVE

Jewelbug APT Runs Espionage and Crypto Fraud Operations Side (TL-2026-2002) is a high-severity tracked intrusion set, first published 2026-08-13. It is attributed to REF7707 (China) with high confidence, affects Google Chrome Browser, maps to 18 MITRE ATT&CK techniques (T1014, T1027.002, T1036.005), and is covered by 9 detection rules and 29 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
18MITRE ATT&CK
Actors
1REF7707
Detection rules
9SPL · KQL · Sigma
IOCs
29Indicators of compromise

Key facts for TL-2026-2002

Threat ID
TL-2026-2002
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
Last reviewed
Attribution
REF7707
Attribution confidence
HIGH
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
government administration, military, telecoms, police - law enforcement, aerospace, industrialmanufacturing
Target regions
Middle East, Southeast Asia, South Asia, taiwan, united states of america
Detection rules
9
Indicators of compromise
29

Malware and tooling in Jewelbug APT Runs Espionage and Crypto Fraud Operations Side

Malware and tooling: Antino, ClientKing, XG-Web, PDF Viewer Extension, XG-Web control panel

How Jewelbug APT Runs Espionage and Crypto Fraud Operations Side works

Jewelbug (aka Earth Alux, REF7707, CL-STA-0049), a China-based hackers-for-hire group, operates a dual-purpose campaign combining nation-state espionage and cryptocurrency fraud from a single XG-Web control panel. In under three months the operation logged over 1 million implant check-ins and stole 580,000+ browser cookies via watering-hole attacks, a malicious PDF Viewer browser extension, and Antino/ClientKing malware, targeting government ministries, militaries, and state telecom providers across the Middle East, Southeast Asia, South Asia, and Taiwan.

Jewelbug is a China-based, hackers-for-hire APT cluster tracked independently as Earth Alux (Trend Micro), REF7707 (Elastic Security Labs), and CL-STA-0049 (Palo Alto Networks Unit 42), first tied together as one actor by Symantec/security.com reporting in October 2025. Operator tradecraft — a registered Hunan Province (Changsha) company, panel accounts 'admin'/'admin_s', the display handle 'ople500', an SEO business contact 'paopaodada' ('Bubble Boss'), an internal 'Xg Team' signature, government-issued identity documents tied to operators, UTC+8 working hours, and VPN egress configured to bypass mainland-Chinese destinations — supports high-confidence China attribution.

The newly documented campaign runs two missions from one control plane: the XG-Web platform, a React-over-Node.js panel backed by MySQL that the operators internally describe as a 'penetration-testing platform' with 'browser hijacking,' 'data theft,' and 'man-in-the-middle attack' functions. XG-Web serves freshly XOR-obfuscated payloads and runs scheduled VirusTotal reputation checks on its own domains every 12 hours. The malicious 'PDF Viewer' Chrome/Firefox extension requests cookie, scripting, debugger, webRequest, download, and native-messaging permissions; it hooks login forms, exfiltrates full cookie jars and session tokens in real time, captures history/bookmarks/screenshots/clipboard, and ships a dormant clipboard module for silent cryptocurrency-address swapping. A native-messaging helper disguised as a Microsoft Edge component (com.microsoft.runedge) bridges the extension to a host command shell. The Windows Antino backdoor, delivered via HTA downloaders and fake Adobe Flash/Adobe installers, sideloads the PDF Viewer extension and hides its C2 traffic inside the legitimate Microsoft Graph API. The Rust-based ClientKing implant (37 builds identified) targets x86-64 servers, ARM64 devices, and ASUS consumer routers with an interactive shell, SOCKS pivoting, in-memory kernel-module loading, a companion rootkit, and a PAM-hooking authentication module that steals credentials off su/sudo; it supports five C2 transports including a custom DNS tunnel. Recent ClientKing builds were configured to route through a U.S. aerospace/industrial manufacturer's internal corporate proxy.

The documented Middle East watering-hole chain: operators gained write access to a compromised shared web-hosting platform used by a national telecom/network-services provider, injected a single script tag (disguised as a Google-Fonts asset at fonts.chrorne.com) into a shared webmail template reaching 15+ government tenants, opened a WebSocket to C2 on login, and labeled sessions by the victim's government email address. Confirmed non-compromised targets on Windows hosts matching government domains were then served a fake Adobe Flash update that dropped the Antino backdoor, which sideloaded the PDF Viewer extension for full browser-API and native-messaging shell access; operators subsequently reached an internal Proxmox virtualization-management cluster. Separately, the group hosts obfuscated payloads in public Google Documents (13 live at time of reporting) and used SEO-poisoning (AI-generated articles plus click-fraud bots) to promote look-alike OKX/Binance exchange domains for the crypto-fraud side of the operation, run through a Chinese-registered 'search-ranking rental' front company with 40+ content-management servers and hundreds of impersonation domains.

Scale, from under three months of logged database activity: 1,000,000+ implant check-ins, 580,000+ stolen browser cookies, several thousand captured credentials, 2,300+ exfiltrated email bodies, and roughly 4,300 distinct source IPs, with the heaviest connection volumes from a Southeast Asian state telecom/military network (~87,200), a Middle Eastern national carrier/Starlink-connected range (~53,100), and a second Southeast Asian government ministry network (~15,000). A related, separately reported Jewelbug intrusion (Jan-May 2025) into a Russian IT service provider's code repositories and build systems — using cdb.exe shellcode execution, ShadowPad, FINALDRAFT/Squidoor, VARGEIT, and Yandex Cloud exfiltration — corroborates the same actor's broader tradecraft but is tracked as a distinct campaign from the dual espionage/crypto-fraud operation documented here.

MITRE ATT&CK techniques used in TL-2026-2002

Defense Evasion

T1014 Rootkit; T1027.002 Obfuscated Files or Information: Software Packing; T1036.005 Match Legitimate Resource Name or Location

Credential Access

T1056.003 Input Capture: Web Portal Capture; T1539 Steal Web Session Cookie; T1556.003 Modify Authentication Process: Pluggable Authentication Modules

Execution

T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1204.002 User Execution: Malicious File

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1071.004 Application Layer Protocol: DNS; T1090.002 Proxy: External Proxy; T1102.001 Web Service: Dead Drop Resolver

Collection

T1113 Screen Capture

Persistence

T1176 Software Extensions

Discovery

T1217 Browser Information Discovery

Resource Development

T1584.004 Compromise Infrastructure: Server; T1608.006 Stage Capabilities: SEO Poisoning

Impact

T1657 Financial Theft

Affected products and versions in Jewelbug APT Runs Espionage and Crypto Fraud Operations Side

  • Google — Chrome Browser
    Vulnerable versions: all versions - compromise via user-installed malicious 'PDF Viewer' extension, not a browser CVE
  • Mozilla — Firefox Browser
    Vulnerable versions: all versions - compromise via user-installed malicious 'PDF Viewer' extension, not a browser CVE
  • ASUS — Consumer routers (ClientKing implant target)
    Vulnerable versions: unspecified consumer router models - implant deployment requires existing admin/root access, not a router CVE
  • Generic — Linux x86-64 servers and ARM64 devices
    Vulnerable versions: N/A - post-compromise ClientKing implant deployment, not a software vulnerability

Remediation for Jewelbug APT Runs Espionage and Crypto Fraud Operations Side

Patches

  • No CVE-based vendor patch applies — this is a malware/TTP-driven campaign (malicious extension, HTA downloaders, fake installers, implant deployment), not a software vulnerability; mitigation is detection- and infrastructure-blocking-based

Immediate actions

  • Block identified C2 domains and IPs at the network perimeter: fonts.chrorne.com, microsoft-flash.com, www.f1ash.org.cn, www.wps-cn.com, mailbycloud.com, 103.87.9.62, 152.42.174.151, 43.246.208.236, 43.246.208.179, 47.84.37.113
  • Audit installed browser extensions and remove any 'PDF Viewer' extension or other extension requesting native-messaging, debugger, and webRequest permissions from an unverified source
  • Force-expire and rotate session cookies for webmail and internal web portals following any suspected watering-hole exposure
  • Hunt for the native-messaging host manifest com.microsoft.runedge and for Antino dropper filenames (flashcenter_pp_ax_install_en.exe, Adobeinstall.exe, flashcenter_pp_ax_install_cn.exe)

Workarounds

  • Disable browser native-messaging support for non-essential/unmanaged extensions
  • Restrict remote management interfaces on ASUS/consumer routers and monitor for unauthorized kernel module loads
  • Treat fake Adobe Flash/Adobe update prompts as malicious by default; Flash is end-of-life and should never be prompted for installation

Longer-term hardening

  • Deploy enterprise browser-extension allowlisting/policy controls to block unauthorized native-messaging hosts
  • Monitor outbound Microsoft Graph API and WebSocket traffic for anomalous beaconing patterns consistent with living-off-trusted-services C2
  • Implement DNS query monitoring/anomaly detection to catch DNS-tunneling C2 consistent with ClientKing
  • Add PAM/authentication-stack integrity monitoring on Linux hosts to detect su/sudo hooking
  • Restrict and monitor administrative access to shared web-hosting/webmail template infrastructure to prevent watering-hole script injection

Timeline of Jewelbug APT Runs Espionage and Crypto Fraud Operations Side

  • Jewelbug cluster (later also tracked as Earth Alux/REF7707/CL-STA-0049) first observed active, predominantly in the APAC region, per Trend Micro reporting (Q2 2023, exact day approximate).
  • Cluster activity expands into Latin America (mid-2024), per Trend Micro/Industrial Cyber reporting (exact day approximate).
  • Related Jewelbug intrusion begins against a Russian IT service provider, gaining access to code repositories and software build systems (separate campaign from the dual espionage/crypto-fraud operation).
  • Most recent confirmed activity observed on the Russian IT service provider's network before detection and remediation.
  • security.com/Symantec publishes 'Jewelbug: Chinese APT Group Widens Reach to Russia,' the first report tying the CL-STA-0049 (Unit 42) and REF7707 (Elastic) clusters to Jewelbug/Earth Alux.
  • Approximate start of the 'under three months' window of dual espionage/crypto-fraud database activity logged prior to the 2026-08-13 report, during which 1,000,000+ implant check-ins and 580,000+ browser cookies were recorded (exact day approximate, derived from report's stated observation window).
  • security.com publishes 'Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side,' detailing the single XG-Web control panel administering both missions, the Antino/ClientKing/PDF Viewer Extension malware set, the Middle East government-webmail watering-hole chain, and the OKX/Binance-impersonation crypto-fraud infrastructure.

Sources cited for Jewelbug APT Runs Espionage and Crypto Fraud Operations Side

Detection coverage for TL-2026-2002

As of 2026-08-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2002 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
29 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-2002

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats