# Jewelbug APT Runs Espionage and Crypto Fraud Operations Side by Side

> Jewelbug (aka Earth Alux, REF7707, CL-STA-0049), a China-based hackers-for-hire group, operates a dual-purpose campaign combining nation-state espionage and cryptocurrency fraud from a single XG-Web control panel. In under three months the operation logged over 1 million implant check-ins and stole 580,000+ browser cookies via watering-hole attacks, a malicious PDF Viewer browser extension, and Antino/ClientKing malware, targeting government ministries, militaries, and state telecom providers across the Middle East, Southeast Asia, South Asia, and Taiwan.

- **Published:** 2026-08-13T00:00:00Z
- **Last reviewed:** 2026-08-13T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2002
- **ID:** TL-2026-2002
- **Severity:** HIGH
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Actor:** REF7707 (China)
- **Detections:** 9 · **IOCs:** 29 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Jewelbug is a China-based, hackers-for-hire APT cluster tracked independently as Earth Alux (Trend Micro), REF7707 (Elastic Security Labs), and CL-STA-0049 (Palo Alto Networks Unit 42), first tied together as one actor by Symantec/security.com reporting in October 2025. Operator tradecraft — a registered Hunan Province (Changsha) company, panel accounts 'admin'/'admin_s', the display handle 'ople500', an SEO business contact 'paopaodada' ('Bubble Boss'), an internal 'Xg Team' signature, government-issued identity documents tied to operators, UTC+8 working hours, and VPN egress configured to bypass mainland-Chinese destinations — supports high-confidence China attribution.

The newly documented campaign runs two missions from one control plane: the XG-Web platform, a React-over-Node.js panel backed by MySQL that the operators internally describe as a 'penetration-testing platform' with 'browser hijacking,' 'data theft,' and 'man-in-the-middle attack' functions. XG-Web serves freshly XOR-obfuscated payloads and runs scheduled VirusTotal reputation checks on its own domains every 12 hours. The malicious 'PDF Viewer' Chrome/Firefox extension requests cookie, scripting, debugger, webRequest, download, and native-messaging permissions; it hooks login forms, exfiltrates full cookie jars and session tokens in real time, captures history/bookmarks/screenshots/clipboard, and ships a dormant clipboard module for silent cryptocurrency-address swapping. A native-messaging helper disguised as a Microsoft Edge component (com.microsoft.runedge) bridges the extension to a host command shell. The Windows Antino backdoor, delivered via HTA downloaders and fake Adobe Flash/Adobe installers, sideloads the PDF Viewer extension and hides its C2 traffic inside the legitimate Microsoft Graph API. The Rust-based ClientKing implant (37 builds identified) targets x86-64 servers, ARM64 devices, and ASUS consumer routers with an interactive shell, SOCKS pivoting, in-memory kernel-module loading, a companion rootkit, and a PAM-hooking authentication module that steals credentials off su/sudo; it supports five C2 transports including a custom DNS tunnel. Recent ClientKing builds were configured to route through a U.S. aerospace/industrial manufacturer's internal corporate proxy.

The documented Middle East watering-hole chain: operators gained write access to a compromised shared web-hosting platform used by a national telecom/network-services provider, injected a single script tag (disguised as a Google-Fonts asset at fonts.chrorne.com) into a shared webmail template reaching 15+ government tenants, opened a WebSocket to C2 on login, and labeled sessions by the victim's government email address. Confirmed non-compromised targets on Windows hosts matching government domains were then served a fake Adobe Flash update that dropped the Antino backdoor, which sideloaded the PDF Viewer extension for full browser-API and native-messaging shell access; operators subsequently reached an internal Proxmox virtualization-management cluster. Separately, the group hosts obfuscated payloads in public Google Documents (13 live at time of reporting) and used SEO-poisoning (AI-generated articles plus click-fraud bots) to promote look-alike OKX/Binance exchange domains for the crypto-fraud side of the operation, run through a Chinese-registered 'search-ranking rental' front company with 40+ content-management servers and hundreds of impersonation domains.

Scale, from under three months of logged database activity: 1,000,000+ implant check-ins, 580,000+ stolen browser cookies, several thousand captured credentials, 2,300+ exfiltrated email bodies, and roughly 4,300 distinct source IPs, with the heaviest connection volumes from a Southeast Asian state telecom/military network (~87,200), a Middle Eastern national carrier/Starlink-connected range (~53,100), and a second Southeast Asian government ministry network (~15,000). A related, separately reported Jewelbug intrusion (Jan-May 2025) into a Russian IT service provider's code repositories and build systems — using cdb.exe shellcode execution, ShadowPad, FINALDRAFT/Squidoor, VARGEIT, and Yandex Cloud exfiltration — corroborates the same actor's broader tradecraft but is tracked as a distinct campaign from the dual espionage/crypto-fraud operation documented here.

## MITRE ATT&CK

- T1584.004 Compromise Infrastructure: Server
- T1608.006 Stage Capabilities: SEO Poisoning
- T1204.002 User Execution: Malicious File
- T1059.003 Command and Scripting Interpreter: Windows Command Shell
- T1176 Software Extensions
- T1014 Rootkit
- T1027.002 Obfuscated Files or Information: Software Packing
- T1036.005 Match Legitimate Resource Name or Location
- T1556.003 Modify Authentication Process: Pluggable Authentication Modules
- T1539 Steal Web Session Cookie
- T1056.003 Input Capture: Web Portal Capture
- T1217 Browser Information Discovery
- T1113 Screen Capture
- T1102.001 Web Service: Dead Drop Resolver
- T1071.001 Application Layer Protocol: Web Protocols
- T1071.004 Application Layer Protocol: DNS
- T1090.002 Proxy: External Proxy
- T1657 Financial Theft

## Sources

- [Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side](https://www.security.com/threat-intelligence/jewelbug-crypto-fraud-espionage)
- [Jewelbug: Chinese APT Group Widens Reach to Russia](https://www.security.com/threat-intelligence/jewelbug-apt-russia)
- [Chinese Threat Group 'Jewelbug' Quietly Infiltrated Russian IT Network for Months](https://thehackernews.com/2025/10/chinese-threat-group-jewelbug-quietly.html)
- [The Espionage Toolkit of Earth Alux: A Closer Look at its Advanced Techniques](https://www.trendmicro.com/en_us/research/25/c/the-espionage-toolkit-of-earth-alux.html)
- [Trend Micro exposes Earth Alux Chinese APT targeting critical infrastructure in APAC, Latin America](https://industrialcyber.co/ransomware/trend-micro-exposes-earth-alux-chinese-apt-targeting-critical-infrastructure-in-apac-latin-america/)
- [Stage Capabilities: SEO Poisoning, Sub-technique T1608.006 - Enterprise | MITRE ATT&CK](https://attack.mitre.org/techniques/T1608/006/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2002
