Jewelbug APT
Summary
Jewelbug is a China-based advanced persistent threat group, also tracked as Earth Alux, REF7707, and CL-STA-0049, that simultaneously conducts state-sponsored espionage against government ministries and a parallel cryptocurrency fraud operation from shared infrastructure. Symantec's Threat Hunter Team (a Broadcom division) published its attribution report on August 13, 2026, documenting over 580,000 stolen browser cookies, more than 2,300 exfiltrated email bodies, and a malicious browser extension capable of silently swapping cryptocurrency wallet addresses at transaction time. No law enforcement action against the group had been announced as of August 2026.
Connected Entities
1 entities · 10 linked investigationsTimeline(7 events)
2013-01-01
Earliest malware samples linked to Jewelbug infrastructure traced to this period, per Symantec analysis.
Security.com (Symantec/Broadcom)2023-04-01
Sustained operational activity confirmed from at least Q2 2023, including espionage and cryptocurrency fraud campaigns.
Crypto Briefing2025-10-01
Group attributed to a five-month intrusion targeting a Russian IT service provider to deliver malware interfering with security tool functionality.
The Hacker News2026-08-13
Symantec's Threat Hunter Team (Broadcom) publishes full attribution report on Jewelbug, disclosing dual espionage and cryptocurrency fraud operations, XG-Web infrastructure details, malware arsenal, operator identity linked to Hunan Province company, and scale of 580,000+ stolen cookies.
Security.com (Symantec/Broadcom)2026-08-13
BleepingComputer, The Hacker News, Crypto Briefing, The Cryptonomist, SC Media, and Infosecurity Magazine publish coverage of the Symantec Jewelbug attribution report.
BleepingComputer2026-08-15
TechTimes and TechNadu publish follow-up analysis of the 15-ministry government webmail compromise and the shared XG-Web panel infrastructure.
TechTimes2026-08-16
No law enforcement action, sanctions designation, or indictment against Jewelbug operators confirmed as of this date.
AVOID.NET research compilationDecision Log
- #1publish⛓ pending8/16/2026, 12:04:25 PMhash: XwK8NptmjHd9hPUy2HAhb7W8NC2Ley7u2AVYXFRxXCa
8 of 12 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/16/2026, 12:04:17 PM
last updated: 8/16/2026, 3:43:02 PM
avoid.net — verified advice for a post-truth world