China-Based Jewelbug Group Runs State Espionage and Crypto Fraud From Single Panel
The hacker-for-hire collective blended high-value government spying with industrial-scale financial crime using a shared command-and-control framework.
The China-based hacker-for-hire group known as Jewelbug has been operating a dual-track cyber campaign, simultaneously conducting state-linked espionage and industrial-scale cryptocurrency fraud. By utilizing a single command-and-control (C2) infrastructure, the group managed to target high-value government assets while running a sophisticated financial scam.
Jewelbug—also identified as Earth Alux and REF7707—targeted government and military organizations across the Middle East, Southeast Asia, and South Asia. To gain access, the group compromised a shared web-hosting platform operated by a national services agency or state telecommunications provider. By injecting a malicious script into a common webmail template, the attackers successfully breached 15 different government webmail tenants.
A Diversified Toolkit
Both the espionage and fraud operations were coordinated through a single C2 panel called XG-Web. The group's technical arsenal is extensive, featuring the Antino backdoor and a Rust-based implant dubbed 'ClientKing,' which specifically targets ASUS routers and Linux servers. To harvest sensitive data, Jewelbug deployed a deceptive 'PDF Viewer' browser extension designed to steal user credentials and browser cookies.
Parallel to its spying efforts, the group operated a massive fraud engine. Jewelbug utilized a fleet of 44 content-management servers and hundreds of lookalike domains to impersonate major cryptocurrency exchanges, including OKX and Binance. To lure victims to these fake platforms, the group employed click-bots and AI-generated content to drive traffic at scale.
The Rise of the Mercenary APT
This operation signals a shift toward 'mercenary' Advanced Persistent Threat (APT) behavior, where the line between state-sponsored intelligence gathering and private profit is blurred. The use of the XG-Web panel for both activities suggests a business-like approach to cybercrime, treating state access and financial theft as complementary revenue streams.
This hybrid model allows the group to maximize the utility of its infrastructure. By leveraging the same framework for both high-stakes espionage and opportunistic theft, Jewelbug reduces the overhead required to maintain separate operations while diversifying its sources of influence and income.
Future Outlook
Security analysts are now monitoring how other hacker-for-hire groups may adopt this hybrid model. While the infrastructure for the current campaign has been identified, the integration of AI-generated lures and the targeting of shared hosting providers demonstrate a scalable method for compromising multiple government entities at once. The industry remains focused on whether other state-linked groups are similarly diversifying their operations into opportunistic financial crime to fund their activities or mask their primary objectives.