Jewelbug Hackers Breach Government Webmail, Run Parallel Crypto Fraud
TL;DR. The China-based Jewelbug hacker group conducted espionage on government webmail while simultaneously running a large-scale cryptocurrency fraud business. - Symantec researchers observed Jewelbug's operations, which targeted government agencies and critical sectors in the Middle East and Asia. - The group used a malicious script on webmail login pages to exfiltrate cookies and deploy malware like Antino and browser extensions. - Jewelbug's C2 data revealed over 1 million implant check-ins and hundreds of thousands of stolen cookies and credentials.
- China-based Jewelbug group (aka Earth Alux, REF7707) conducted dual-purpose operations: government espionage and cryptocurrency fraud.
- The group compromised webmail accounts of 15 government tenants, inserting malicious scripts to steal cookies and deploy malware.
- Symantec researchers gained access to Jewelbug's C2 infrastructure, revealing extensive data exfiltration and victim counts across multiple regions.
Sources
- Hackers breach govt webmail while running parallel crypto fraud — bleepingcomputer.com