Jewelbug Uses XG-Web for Espionage and Crypto Fraud
TL;DR. China-linked threat actor Jewelbug employs custom malware, XG-Web, for government espionage and cryptocurrency fraud, targeting entities with identity exposure. - Jewelbug exploits identified vulnerabilities, combining phishing and supply chain attacks to infiltrate government networks. - The group leverages its custom XG-Web toolkit for persistent access, data exfiltration, and financial manipulation. - Their operations include harvesting credentials, deploying backdoors, and diverting crypto funds from compromised organizations.
- China-linked Jewelbug group deploys XG-Web malware for cyber espionage and crypto theft.
- Attacks involve exploiting identity exposure, phishing, and supply chain compromise to infiltrate targets.
- XG-Web facilitates credential harvesting, data exfiltration, and illicit cryptocurrency transactions.
Sources
- China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud — thehackernews.com