China-Based 'Jewelbug' APT Blurs Line Between State Espionage and Crypto Fraud
Symantec researchers uncover a mercenary hacking group using a single command-and-control panel to target governments and defraud cryptocurrency investors.
A China-based mercenary hacking group known as Jewelbug is simultaneously conducting high-level state espionage and industrial-scale cryptocurrency fraud. The group utilizes a unified infrastructure to target government, military, and telecommunications organizations across Asia and the Middle East while managing hundreds of fraudulent cryptocurrency exchanges.
According to research from Symantec, the group operates both activities through a custom command-and-control (C2) platform called "XG-Web." This panel features role-based access controls—categorized as superadmin, admin, and ordinary users—allowing the group to efficiently manage diverse operations ranging from geopolitical intelligence gathering to financial theft. Their technical arsenal includes "Antino," a Windows backdoor, and "ClientKing," a Linux backdoor. Additionally, the group deploys a malicious browser extension disguised as a "PDF Viewer," designed to steal session tokens and cookies or inject arbitrary JavaScript into target systems.
A Mercenary Model of Espionage
Jewelbug represents a broader shift toward the "hackers-for-hire" model in China, where private contractors are recruited by the state to scale cyber operations. This arrangement provides the state with expanded reach and plausible deniability, though researchers note it often results in weaker operational security compared to dedicated military units.
The group's reach is evidenced by the compromise of a Middle Eastern government, achieved by infiltrating a shared web hosting platform managed by a state-owned telecommunications provider. Once inside, Jewelbug used scripts to steal login cookies and deploy backdoors. More recently, in early 2025, the group spent five months infiltrating a Russian IT service provider, specifically targeting source code repositories in a supply-chain intrusion.
Industrializing Cybercrime
Beyond espionage, Jewelbug has industrialized financial fraud. The group employs AI to generate thousands of phishing sites dedicated to betting and cryptocurrency. This operation is supported by 44 content management servers and the use of click-fraud bots to artificially boost search engine rankings for their fake exchanges.
"The sheer scale of the fraud business is the biggest clue," said Dick O'Brien, principal intelligence analyst for the Symantec Threat Hunter Team. "They aren't just making a little extra money by moonlighting."
Industry Implications
The dual-purpose nature of Jewelbug suggests a highly efficient, mercenary-style operation capable of pivoting between targets based on state priority or the highest bidder. By using a single infrastructure for both state-sponsored spying and criminal theft, the group blurs the traditional boundary between geopolitical conflict and organized cybercrime.
Security professionals are advised to monitor for the specific indicators of the XG-Web panel and the "PDF Viewer" extension. As the mercenary model grows, the industry expects more APTs to adopt this hybrid approach, combining the resources of a nation-state with the agility and greed of private criminal enterprises.