China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud
The China-linked threat actor Jewelbug, operating as a ‘hack-for-hire’ group, is engaged in both sophisticated government espionage targeting nations across the Middle East, Southeast Asia, and South Asia, and cryptocurrency fraud operations targeting Chinese-speaking users. The group utilizes a central control panel, XG-Web, and a suite of tools including a malicious browser extension (PDF Viewer) and backdoors (Antino, ClientKing) to achieve its goals. Jewelbug’s operations are characterized by a unique blend of espionage and criminal activity, highlighting the increasing overlap between nation-state actors and cybercrime groups.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
