Skip to main content
Sign in

Jewelbug APT

avoid.net/jewelbug-apt0/100·87% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·3a6kiY…jhjB

Summary

Jewelbug is a China-based advanced persistent threat group, also tracked as Earth Alux, REF7707, and CL-STA-0049, that simultaneously conducts state-sponsored espionage against government ministries and a parallel cryptocurrency fraud operation from shared infrastructure. Symantec's Threat Hunter Team (a Broadcom division) published its attribution report on August 13, 2026, documenting over 580,000 stolen browser cookies, more than 2,300 exfiltrated email bodies, and a malicious browser extension capable of silently swapping cryptocurrency wallet addresses at transaction time. No law enforcement action against the group had been announced as of August 2026.

Have evidence about Jewelbug APT?

Timeline(7 events)

2013

Earliest malware samples linked to Jewelbug infrastructure traced to this period, per Symantec analysis.

Security.com (Symantec/Broadcom)

April 2023

Sustained operational activity confirmed from at least Q2 2023, including espionage and cryptocurrency fraud campaigns.

Crypto Briefing

October 2025

Group attributed to a five-month intrusion targeting a Russian IT service provider to deliver malware interfering with security tool functionality.

The Hacker News

13 August 2026

Symantec's Threat Hunter Team (Broadcom) publishes full attribution report on Jewelbug, disclosing dual espionage and cryptocurrency fraud operations, XG-Web infrastructure details, malware arsenal, operator identity linked to Hunan Province company, and scale of 580,000+ stolen cookies.

Security.com (Symantec/Broadcom)

13 August 2026

BleepingComputer, The Hacker News, Crypto Briefing, The Cryptonomist, SC Media, and Infosecurity Magazine publish coverage of the Symantec Jewelbug attribution report.

BleepingComputer

15 August 2026

TechTimes and TechNadu publish follow-up analysis of the 15-ministry government webmail compromise and the shared XG-Web panel infrastructure.

TechTimes

16 August 2026

No law enforcement action, sanctions designation, or indictment against Jewelbug operators confirmed as of this date.

AVOID.NET research compilation
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (3 events). 9 of 12 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/16/2026, 12:04:17 PM

last updated: 8/25/2026, 1:06:30 PM

4 views

avoid.net — verified advice for a post-truth world