Chinese APT 'Jewelbug' Linked to Hack-for-Hire and Crypto Fraud Operations
Broadcom researchers have uncovered that the Chinese APT group 'Jewelbug' operates a dual-pronged strategy, engaging in both state-sponsored espionage and lucrative hack-for-hire cryptocurrency fraud schemes.

Broadcom's Threat Hunter Team has revealed a significant evolution in the tactics of the Chinese advanced persistent threat (APT) group known as Jewelbug. Previously associated with cyber espionage targeting governments and militaries across Asia, the group, also identified by aliases such as Ink Dragon, Earth Alux, REF770, and CL-STA-0049, is now believed to be operating a sophisticated hack-for-hire service alongside its espionage activities. This dual operation utilizes shared infrastructure and a single control panel, indicating a strategic consolidation of resources for both state-aligned objectives and financial gain.
The investigation highlights a convergence of cyber espionage and financially motivated cybercrime. Jewelbug leverages the same infrastructure for its espionage campaigns, which have targeted government and military entities in the Middle East, Southeast Asia, and South Asia, as well as for a separate, lucrative operation focused on Chinese-speaking cryptocurrency users. This financially driven venture employs fake exchange-download portals to ensnare victims.
Researchers identified a key operator, using the persona 'ople500' within the group's control panel, who is believed to be responsible for the "commercial arm of the business." This individual has been advertised on Telegram for a "website ranking rental" service and is confidently linked by Broadcom to an SEO business registered in Changsha, China. While the legal representative of this company supplies access and infrastructure, the operators are distinct from this administrative role.
Jewelbug's espionage activities have been previously documented by various security firms. Their typical entry vector involves exploiting vulnerable Internet Information Services (IIS) and SharePoint servers, followed by the deployment of web shells and a sophisticated backdoor known as VARGEIT, Squidoor, or FinalDraft. This malware supports multiple command-and-control (C2) methods, including Microsoft Graph/Outlook APIs and DNS/ICMP tunneling, allowing for covert communication.
The scale of Jewelbug's operations is substantial. In less than three months, researchers observed over one million implant check-ins and more than 580,000 stolen browser cookies. One notable espionage campaign involved placing a watering-hole script across more than 15 government webmail tenants in a Middle Eastern country simultaneously. The group's common targets include government communications systems and their hosting providers, suggesting a strategy for long-term access to sensitive information.
Central to both the espionage and fraud operations is XG-Web, a browser-based C2 platform that serves as the group's central management console. This shared infrastructure facilitates the administration of victims from both campaigns, with data and operator activity feeding into a unified backend database. The Antino backdoor, which communicates via the Microsoft Graph API to blend with legitimate traffic, is a primary tool connected to this ecosystem.
Beyond Antino, Jewelbug also deploys malicious browser extensions like 'PDF Viewer' and a helper program disguised as a Microsoft Edge component. This combination grants extensive access to victims' browsers, enabling the theft of cookies, credentials, and browsing data, and can establish a command shell. For Linux and router compromises, the group uses ClientKing, which supports various C2 methods and offers remote shell access. The group has also been observed abusing Google Docs for payload delivery and C2, masking malicious activity within legitimate Google infrastructure.
The convergence of state-sponsored espionage with financially motivated cybercrime, particularly in the cryptocurrency space, represents a growing trend among sophisticated threat actors. Jewelbug's ability to maintain dual operations from shared infrastructure underscores the evolving landscape of cyber threats, where the lines between nation-state activity and organized criminal enterprises are increasingly blurred.