
Symantec says Chinese hacker group Jewelbug runs state espionage and AI-generated fake crypto exchanges from the same infrastructure, targeting over a million victims across multiple continents.
Alpha Score of 57 reflects moderate overall profile with strong momentum, poor value, strong quality. Based on 3 of 4 signals – score is capped at 90 until remaining data ingests.
A Chinese hacker-for-hire group called Jewelbug has been running government espionage campaigns and cryptocurrency fraud operations off the same infrastructure, Symantec's Threat Hunter Team reported. The group's centralized command-and-control system, XG-Web, has tracked over one million implant check-ins across its victim database. Jewelbug stole more than 580,000 browser cookies and exfiltrated over 2,300 email bodies.
Active since mid-2023, Jewelbug also operates as Earth Alux and REF7707. Its espionage work targets government entities in the Middle East, Southeast Asia, South Asia, and Taiwan. One campaign planted a malicious script across more than 15 government webmail tenants on a shared hosting platform, a technique called a waterhole attack.
Spying on diplomats is half the operation. On the financial crime side, the group has registered hundreds of lookalike domains and created thousands of fake downloads for crypto exchanges. These fraudulent sites are generated with AI and primarily target Chinese-speaking victims, Symantec said.
The crypto fraud arm relies on a malicious browser extension that does more than harvest credentials. It includes a clipboard module that swaps cryptocurrency wallet addresses without the user noticing. A victim copies an intended wallet address and pastes it into a transaction. The extension quietly replaces it with an address controlled by Jewelbug.
Jewelbug's technical arsenal includes the Antino Windows backdoor and the browser extension, both custom-built. The group also uses SEO poisoning, manipulating search engine results to push malicious websites to the top of searches for popular crypto platforms.
The XG-Web command-and-control platform serves as the operational nerve center. It simultaneously manages espionage implants on government systems and coordinates the fake crypto exchange campaigns. Prior reports dating back to October 2025 had flagged Jewelbug's attacks on geopolitical targets. The crypto fraud dimension adds a new layer.
The clipboard-swapping technique exploits a step most users consider safe. Copying and pasting a wallet address feels like a security measure, a way to avoid typos. Jewelbug turns that habit into a vulnerability.
The SEO poisoning campaigns compound the problem. The registration of hundreds of lookalike domains suggests this is a dragnet, not a targeted operation. For crypto users, the practical risk is straightforward: any site that looks like a legitimate exchange but isn't the exact URL could be a Jewelbug front. Symantec's report did not name specific exchanges targeted.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.