Jewelbug APT
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·3a6kiY…jhjBSummary
Jewelbug is a China-based advanced persistent threat group, also tracked as Earth Alux, REF7707, and CL-STA-0049, that simultaneously conducts state-sponsored espionage against government ministries and a parallel cryptocurrency fraud operation from shared infrastructure. Symantec's Threat Hunter Team (a Broadcom division) published its attribution report on August 13, 2026, documenting over 580,000 stolen browser cookies, more than 2,300 exfiltrated email bodies, and a malicious browser extension capable of silently swapping cryptocurrency wallet addresses at transaction time. No law enforcement action against the group had been announced as of August 2026.
Connected Entities
1 entities · 10 linked investigationsTimeline(7 events)
2013
Earliest malware samples linked to Jewelbug infrastructure traced to this period, per Symantec analysis.
Security.com (Symantec/Broadcom)April 2023
Sustained operational activity confirmed from at least Q2 2023, including espionage and cryptocurrency fraud campaigns.
Crypto BriefingOctober 2025
Group attributed to a five-month intrusion targeting a Russian IT service provider to deliver malware interfering with security tool functionality.
The Hacker News13 August 2026
Symantec's Threat Hunter Team (Broadcom) publishes full attribution report on Jewelbug, disclosing dual espionage and cryptocurrency fraud operations, XG-Web infrastructure details, malware arsenal, operator identity linked to Hunan Province company, and scale of 580,000+ stolen cookies.
Security.com (Symantec/Broadcom)13 August 2026
BleepingComputer, The Hacker News, Crypto Briefing, The Cryptonomist, SC Media, and Infosecurity Magazine publish coverage of the Symantec Jewelbug attribution report.
BleepingComputer15 August 2026
TechTimes and TechNadu publish follow-up analysis of the 15-ministry government webmail compromise and the shared XG-Web panel infrastructure.
TechTimes16 August 2026
No law enforcement action, sanctions designation, or indictment against Jewelbug operators confirmed as of this date.
AVOID.NET research compilationDecision Log
- hash: 2UmHbv6KDw58BrQcXSs4EFE4ADHsYj2sqY4ytBeGZq7c
- hash: 5DoiTtgVxge8mksfxkfC9mRYRs9yxgRg1Xapr86B2mKZ
- hash: XwK8NptmjHd9hPUy2HAhb7W8NC2Ley7u2AVYXFRxXCa
This investigation is cryptographically anchored to the Solana blockchain (3 events). 9 of 12 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/16/2026, 12:04:17 PM
last updated: 8/25/2026, 1:06:30 PM
4 viewsavoid.net — verified advice for a post-truth world