Jewelbug is a China-based APT group that operates government espionage and cryptocurrency fraud campaigns from a shared infrastructure and single control panel called XG-Web. The group uses a malicious browser extension named 'PDF Viewer' that bridges to the host via a native messaging host disguised as com.microsoft.runedge, the Antino backdoor which uses Microsoft Graph API for C2, and ClientKing, a Rust implant targeting Linux servers and routers. In its largest operation, Jewelbug injected a watering-hole script into a shared government webmail platform, compromising more than 15 tenants simultaneously and harvesting credentials, cookies, and email bodies from government officials.
jewelbug
1 post
Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side