Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2368+ Articles
158+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Hackers Breach Govt Webmail While Running Parallel Crypto Fraud
Hackers Breach Govt Webmail While Running Parallel Crypto Fraud
NEWS

Hackers Breach Govt Webmail While Running Parallel Crypto Fraud

China-linked Jewelbug injected malicious JS into 15 govt webmail tenants while simultaneously operating a 44-server industrial crypto fraud empire.

Dylan H.

News Desk

August 13, 2026
5 min read

Overview

The Jewelbug threat actor — also tracked as Earth Alux and REF7707 — has been conducting simultaneous espionage and large-scale cryptocurrency fraud operations, blending nation-state intelligence collection with financially-motivated crime. A detailed Symantec report published August 13, 2026 reveals that the China-linked group injected malicious JavaScript into a shared government webmail platform, compromising 15 separate government ministry tenants through a single injection point, while concurrently operating a 44-server content-management fleet running industrial-scale fake crypto exchanges.

The dual-track operation illustrates an increasingly documented trend: APT actors supplementing espionage mandates with financially motivated fraud run from the same infrastructure and control panels.


Threat Actor Profile

AttributeDetail
Group NameJewelbug (a.k.a. Earth Alux, REF7707)
AttributionChina-nexus; linked to a company advertising SEO services
OperationsDual: government espionage + industrial cryptocurrency fraud
Regions TargetedMiddle East, Southeast Asia, South Asia
SectorsGovernment, military, defense, telecommunications, education, aviation

Government Webmail Breach

Attack Method: Supply Chain-Style Template Injection

Rather than targeting individual government ministries directly, Jewelbug took a supply chain approach:

  1. Compromised a shared web-hosting platform operated by a state telecommunications provider
  2. Gained write access to a shared webmail installation serving multiple government ministry tenants
  3. Injected a single <script> tag into the common webmail template — one insertion point that propagated instantly to all tenants
  4. The malicious JavaScript established WebSocket connections to Jewelbug's C2 server
  5. The script ran on both login pages and mailbox views across 15 government webmail tenants
  6. Collected webmail session cookies and user email addresses to identify and prioritize high-value government domains

Scale of Collection (from exposed victim database)

Data TypeVolume
Implant check-in rows1,000,000+
Stolen browser cookies580,000+
Captured credentialsSeveral thousand
Exfiltrated email bodies2,300+
Geolocation events~1.1 million (from ~4,300 distinct IPs)

Geographic Targeting

  • Middle East: Government ministries, national carrier networks, Starlink-connected addresses in capital cities
  • Southeast Asia: State telecom and military networks, government ministry infrastructure
  • South Asia: Government and military organizations

Parallel Cryptocurrency Fraud Operation

Running concurrently from the same infrastructure, Jewelbug operated what researchers describe as an industrial-scale cryptocurrency fraud business:

  • AI-generated articles funneling organic search traffic to fake crypto exchanges impersonating OKX and Binance
  • An automated pipeline scraping keywords and generating thousands of fake download pages for the fraudulent exchanges
  • A 44-server content-management fleet with hundreds of lookalike domains mimicking legitimate financial platforms
  • Click-fraud bots manipulating search engine rankings to keep the fraudulent sites visible
  • Additional fraud lures: sports betting sites, pirated livestream portals, and private detective scam services

Attribution links the fraud operation to a Chinese company advertising SEO services, suggesting the criminal enterprise may be operating under a commercial facade while also serving intelligence objectives.


Malware and Tools

ToolDescription
Antino BackdoorDelivered via malicious HTA files and fake Adobe Flash installers; deploys additional payloads on infected hosts
Malicious PDF Viewer ExtensionBrowser extension (Chrome + Firefox) that steals cookies and credentials, intercepts traffic, injects JavaScript, and remotely exposes browser APIs
ClientKingRust-based implant targeting Linux servers, ARM64 devices, and ASUS routers; supports command execution, SOCKS proxying, DNS tunneling, and in-memory kernel module loading
XG-Web FrameworkRemote access and data theft framework for campaign management and victim tracking

Additional TTPs:

  • Public Google Docs used to host obfuscated payloads (abusing trusted infrastructure)
  • Fake Adobe Flash update prompts as initial access lures for desktop targets
  • Watering hole methodology via the shared webmail template injection

Why This Matters

The Jewelbug operation is notable for several reasons:

1. Single-point supply chain compromise: A single template injection across a shared hosting platform compromised 15 separate government organizations simultaneously. This is a force-multiplier attack that bypasses the need to target each ministry individually.

2. Dual-track APT model: The concurrent operation of espionage and large-scale financial fraud from the same infrastructure suggests that at least some China-linked actors are either self-funding through crime or operating under broader mandates that include financially motivated operations. This complicates attribution and deterrence.

3. Scale of data collection: 580,000+ stolen cookies and over a million implant check-ins represents an enormous passive collection operation that can fuel months of follow-on targeting.

4. Rust-based cross-platform tooling: The ClientKing implant's Rust implementation and targeting of ASUS routers and ARM64 devices signals investment in cross-platform persistence, including network infrastructure typically outside traditional endpoint security scope.


Defensive Recommendations

  1. Audit shared hosting and webmail platforms — especially those serving multiple government or sensitive organizational tenants. A single template compromise is a breach of all tenants.
  2. Implement Content Security Policy (CSP) headers to restrict script injection and unauthorized WebSocket connections on webmail platforms
  3. Monitor WebSocket traffic patterns from webmail and collaboration platforms for unexpected external connections
  4. Hunt for the named implants: Antino, ClientKing, and the malicious PDF Viewer Extension. Symantec has published IOCs.
  5. Audit ASUS routers and ARM64 network devices for unauthorized processes or unexpected outbound connections consistent with ClientKing
  6. Train users on fake crypto exchange phishing — the scale of lookalike domains means employees may encounter them in personal browsing or on corporate devices

References

  • BleepingComputer — Hackers breach govt webmail while running parallel crypto fraud
  • Symantec Threat Intelligence — Jewelbug / Earth Alux Technical Report
#APT#Espionage#Cryptocurrency Fraud#China#Webmail#Supply Chain#Data Breach

Related Articles

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

Cybersecurity researchers at Expel have attributed the April 2026 DigiCert security incident to CylindricalCanine, a sub-group of the Chinese APT known as...

4 min read

Chinese Hackers Breach REDCap Servers, Steal Medical Research Data

A China-linked espionage campaign targeted exposed REDCap servers, deploying the InfiniteRed malware to steal sensitive medical research data from a North...

4 min read

China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade

Sygnia researchers uncovered Velvet Ant, a China-nexus APT that spent close to a decade hidden inside Linux authentication infrastructure by backdooring...

6 min read
Back to all News