Skip to main content
← All threats
CRITICAL Published August 13, 2026

APT Group Runs Espionage and Crypto Fraud Operations Side by Side

Jewelbug is a China-based hackers-for-hire group conducting parallel operations: espionage campaigns targeting government ministries and militaries across the Middle East, Southeast Asia, and South Asia, alongside a cryptocurrency fraud business. Both missions operate from a single control panel called XG-Web, a browser-centric remote-access framework. The group's main implant is the Antino backdoor, complemented by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. Their largest operation compromised over 15 government webmail tenants in a Middle Eastern country through a single watering-hole attack. The victim database recorded over one million implant check-ins and 580,000 stolen browser cookies within three months. Operators are linked to a registered Hunan Province company, with infrastructure supporting both espionage and commercial SEO poisoning operations targeting Chinese-speaking cryptocurrency users.

Jewelbug is a China-based hackers-for-hire group conducting parallel operations: espionage campaigns targeting government ministries and militaries across the Middle East, Southeast Asia, and South Asia, alongside a cryptocurrency fraud business. Both missions operate from a single control panel called XG-Web, a browser-centric remote-access framework. The group's main implant is the Antino backdoor, complemented by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. Their largest operation compromised over 15 government webmail tenants in a Middle Eastern country through a single watering-hole attack. The victim database recorded over one million implant check-ins and 580,000 stolen browser cookies within three months. Operators are linked to a registered Hunan Province company, with infrastructure supporting both espionage and commercial SEO poisoning operations targeting Chinese-speaking cryptocurrency users.

MITRE ATT&CK

Tactics, Techniques & Procedures

TA0010 Exfiltration tactic
TA0001 Initial Access tactic

Defensive mapping

Mapped controls

The audit will verify each of these controls is in place and effective.

Control Confidence Why it matters
Data loss prevention (DLP) suggested 75% Recommended control for data_breach
Encryption at rest suggested 75% Recommended control for data_breach
Privileged access management (PAM) suggested 75% Recommended control for data_breach
Logging and alerting suggested 75% Recommended control for data_breach
Incident response readiness suggested 75% Recommended control for data_breach