Jewelbug APT Parallel Espionage and Crypto Fraud
Score: 8/10

Jewelbug APT Parallel Espionage and Crypto Fraud

China-based Jewelbug APT utilizes the XG-Web platform to conduct dual-mission operations involving government espionage across the Middle East and Asia alongside large-scale cryptocurrency fraud.

Executive Summary

Jewelbug (also known as Earth Alux or REF7707) is a China-based hackers-for-hire group that maintains a unique operational profile by running espionage campaigns against government ministries and militaries alongside a commercial cryptocurrency fraud business. The group leverages a unified control panel, XG-Web, to manage multiple malware families, including the Antino backdoor and the ClientKing Linux/router implant.

Technically, the group employs sophisticated delivery methods such as watering-hole attacks on government webmail systems and SEO poisoning to lure victims to fake cryptocurrency exchange portals. They utilize legitimate cloud infrastructure, such as Google Docs for payload delivery and the Microsoft Graph API for command-and-control (C&C), to evade detection. The operation is tied to a registered company in Hunan Province, China, indicating a commercialized hack-for-hire model.

This threat is significant due to its massive scale, with over one million recorded implant check-ins and the successful compromise of shared national hosting providers. The group's ability to pivot from browser-based hooks to internal virtualization clusters poses a high risk to government integrity and sensitive corporate data in targeted regions.

Key Details

Threat Name

Jewelbug APT

Affects

—

Adversary

Jewelbug

Malware/Tools

Antino, XG-Web, ClientKing, PDF Viewer

Report Score

8out of 10
Quality Score
Good
IOC Quality9
TTP Details9
Detection Guidance4
Enterprise Relevance9
Clarity & Structure10
Technical Depth8

Sources