Executive Summary
Jewelbug (also known as Earth Alux or REF7707) is a China-based hackers-for-hire group that maintains a unique operational profile by running espionage campaigns against government ministries and militaries alongside a commercial cryptocurrency fraud business. The group leverages a unified control panel, XG-Web, to manage multiple malware families, including the Antino backdoor and the ClientKing Linux/router implant.
Technically, the group employs sophisticated delivery methods such as watering-hole attacks on government webmail systems and SEO poisoning to lure victims to fake cryptocurrency exchange portals. They utilize legitimate cloud infrastructure, such as Google Docs for payload delivery and the Microsoft Graph API for command-and-control (C&C), to evade detection. The operation is tied to a registered company in Hunan Province, China, indicating a commercialized hack-for-hire model.
This threat is significant due to its massive scale, with over one million recorded implant check-ins and the successful compromise of shared national hosting providers. The group's ability to pivot from browser-based hooks to internal virtualization clusters poses a high risk to government integrity and sensitive corporate data in targeted regions.
