Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies

August 14, 2026

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

August 14, 2026

Researchers Link Suspected Chinese APT to Hack-for-Hire Operations

August 14, 2026
Facebook X (Twitter) Instagram
Friday, August 14
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Researchers Link Suspected Chinese APT to Hack-for-Hire Operations
News

Researchers Link Suspected Chinese APT to Hack-for-Hire Operations

Team-CWDBy Team-CWDAugust 14, 2026No Comments5 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Security researchers from Broadcom’s Threat Hunter Team have revealed that Jewelbug, a threat group associated with Chinese-sponsored cyber espionage operations, may be a hacker-for-hire group that also runs profitable crypto fraud campaigns.

In a new report published on August 13, the threat intelligence team – which brought  together experts from Symantec and Carbon Black – shed new light on the advanced persistent threat (APT) group, also known as Ink Dragon, Earth Alux, REF770 and CL-STA-0049.

The researchers revealed that Jewelbug uses the same infrastructure to conduct espionage against governments and militaries across the Middle East, Southeast Asia and South Asia as well as a financially motivated operation targeting Chinese-speaking cryptocurrency users through fake exchange-download portals.

“The two are not separate ventures that happen to share a name: our investigation revealed they are run by the same small team, on shared infrastructure, from one control panel,” the Broadcom report noted.

At least one of the operators, likely running what Broadcom described as “the commercial arm of the business,” identified as ‘ople500’ in the group’s control panel, has been identified as using the ‘paopaodada’ (‘bubble boss’) persona.

This individual has been advertised on Telegram as the contact for a “website ranking rental” service. Broadcom associated the individual “with high confidence” to a company, described as an SEO business, registered in Changsha, the capital of the Hunan province.

The Threat Hunter Team has identified the name of the sole legal representative of this company and assessed that that person supplies access, infrastructure and delivery to the espionage operation rather than being part of the team of operators. 

Cyber Espionage Targets

Jewelbug’s cyber espionage operations had already been reported by various threat intelligence teams, including Trend Micro’s TrendAI, Palo Alto Networks’ Unit 42 and Check Point Research.

Researchers found the actor typically gained access through vulnerable IIS and SharePoint servers before deploying web shells and a sophisticated backdoor tracked as VARGEIT, Squidoor or FinalDraft.

The malware supported multiple covert command-and-control (C2) methods, including Microsoft Graph/Outlook APIs, DNS tunnelling and ICMP tunnelling.

After a months-long investigation into some of the threat group’s operations, Broadcom researchers found it has targeted several government organizations across the Middle East and Southeast Asia, with more than 90 police and government email addresses in South Asia.

They also found a victim database which recorded more than one million implant check-ins and over 580,000 stolen browser cookies in less than three months of active operations.

One set of implants was configured to utilize the internal proxy of a major US aerospace and industrial manufacturer.

In its largest operation, a single planted script placed a watering-hole on more than 15 government webmail tenants in a Middle Eastern country at once.

Crypto Fraud Targets

Meanwhile, some of Jewelbug’s infrastructure was used to run a cryptocurrency fraud business on the side.

The Broadcom researchers said the group operated a financially motivated campaign targeting Chinese-speaking cryptocurrency users through fake exchange-download websites, while decoy documents themed around Taiwanese government organizations suggested it also had an interest in Taiwan.

The report added that the common thread across the group’s espionage targets was government communications systems and the service providers that host them, potentially providing long-term access to official correspondence.

Jewelbug’s Common Infrastructure for Espionage and Fraud

At the center of both the espionage and cryptocurrency fraud operations was XG-Web, a browser-based C2 platform that acted as the group’s central management console.

According to the Broadcom report, the same XG-Web infrastructure was used to administer victims from both campaigns, with implants, stolen data and operator activity all feeding into a shared backend database.

One of the primary tools connected to this infrastructure was Antino, the group’s Windows backdoor.

Antino communicated with operators through the Microsoft Graph API, allowing C2 traffic to blend in with legitimate Microsoft cloud services.

The Broadcom report said the malware was used across multiple Jewelbug campaigns and was deployed through fake software installers and themed lures.

The group also operated a malicious Chrome and Firefox extension called ‘PDF Viewer,’ which was paired with a helper program disguised as a Microsoft Edge component. The combination gave operators extensive access to victims’ browsers, enabling them to steal cookies, credentials and browsing data, while also providing a command shell on the compromised host through a native messaging component.

Alongside Antino, Jewelbug used a Linux and router implant known as ClientKing, which supported multiple C2 methods, including DNS tunnelling and provided remote shell access and pivoting capabilities.

The researchers noted that ClientKing infrastructure overlapped with the group’s wider XG-Web ecosystem, further linking the espionage and fraud operations.

Finally, the group also abused Google Docs for payload delivery and C2. When operators launched a campaign, the backend created public Google documents containing obfuscated payloads, which implants would retrieve and execute. By leveraging Google’s infrastructure, the group was able to disguise malicious activity as legitimate traffic and reduce the likelihood of detection.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleNew WordPress Pre-Auth XSS Could Lead to PHP Code Execution
Next Article UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
Team-CWD
  • Website

Related Posts

News

New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies

August 14, 2026
News

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

August 14, 2026
News

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution

August 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

July 11, 20268 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

How to tell if a voice call is AI or not

February 23, 2026

Find your weak spots before attackers do

November 21, 2025

‘What happens online stays online’ and other cyberbullying myths, debunked

September 11, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.