Jewelbug Hackers Breach Government Webmail, Run Parallel Crypto Fraud

TL;DR. The China-based Jewelbug hacker group conducted espionage on government webmail while simultaneously running a large-scale cryptocurrency fraud business. - Symantec researchers observed Jewelbug's operations, which targeted government agencies and critical sectors in the Middle East and Asia. - The group used a malicious script on webmail login pages to exfiltrate cookies and deploy malware like Antino and browser extensions. - Jewelbug's C2 data revealed over 1 million implant check-ins and hundreds of thousands of stolen cookies and credentials.

Sources

Back to QLANKR News