← Jewelbug APT1 decision on this page
Audit log
Every state-changing event for Jewelbug APT: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-16 12:04:25ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
XwK8NptmjHd9…YXFRxXCasha256 → base58
verifying row…canonical bytes (21862 B) ▸
{"actor":"system:backfill","investigation_id":"d85d31d4-5ac7-4267-8d7f-95285282f1a9","kind":"publish","page_slug":"jewelbug-apt","published_at":"2026-08-16T12:04:25.915Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Jewelbug APT","sections":[{"content":"Symantec's Threat Hunter Team attributed Jewelbug to China-based operators on August 13, 2026, in a report published under Broadcom's security research division. The group overlaps with threat clusters independently tracked as Earth Alux (Trend Micro), REF7707 (Elastic Security Labs), CL-STA-0049 (Palo Alto Networks Unit 42), and Ink Dragon (Check Point Research). Symantec's investigation identified at least one operator linked to a registered company in Hunan Province, specifically in Changsha, through government-issued identity documents, a company business license, and signed authorization letters recovered from the group's own infrastructure. That individual allegedly advertised 'website ranking rental' services on Telegram under the handle 'paopaodada' (translated as 'Bubble Boss') and reused that handle as the administrator login across the fleet of content management servers running the crypto fraud operation. Symantec assessed that the SEO and infrastructure business supplied access and delivery capability to the espionage operation but noted that the precise relationship between the identified individual and the operators conducting the government hacking campaigns was not fully established. The group works primarily during afternoons and late evenings in the UTC+8 time zone. Malware samples traced to the group date as far back as 2013, though sustained operational activity was confirmed from at least the second quarter of 2023.","heading":"Attribution and Identity","severity":"critical","sources":[{"credibility":1,"name":"Jewelbug APT Group Runs Espionage and Crypto Fraud Operations Side by Side — Security.com (Symantec/Broadcom)","type":"research","url":"https://www.security.com/threat-intelligence/jewelbug-crypto-fraud-espionage"},{"credibility":2,"name":"China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"},{"credibility":2,"name":"Hackers breach govt webmail while running parallel crypto fraud — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/hackers-breach-govt-webmail-while-running-parallel-crypto-fraud/"}]},{"content":"Jewelbug's operations are unified through a proprietary platform called XG-Web, described internally as 'Xiang Ge — Security Testing Platform.' Internal documentation recovered by Symantec listed its actual functions as 'browser hijacking,' 'data theft,' and 'man-in-the-middle attack.' The platform is built on a React front-end with a Node.js backend and MySQL database. XG-Web serves as a browser-centric remote-access and information-stealing framework capable of managing campaigns across compromised browsers, Windows endpoints, Linux servers, and network devices simultaneously. The panel incorporates automated operational security measures, including checking its own infrastructure against VirusTotal every 12 hours to enable rapid domain rotation when detection occurs. Operators also used public Google Docs to host obfuscated payloads encoded with random XOR keys, and used typosquatting domains mimicking Google Fonts as command-and-control relay points. Both the espionage and cryptocurrency fraud arms of the operation are administered from this single shared panel, which Symantec described as 'the combination of two missions in one set of hands.'","heading":"XG-Web Command-and-Control Infrastructure","severity":"critical","sources":[{"credibility":1,"name":"Jewelbug APT Group Runs Espionage and Crypto Fraud Operations Side by Side — Security.com (Symantec/Broadcom)","type":"research","url":"https://www.security.com/threat-intelligence/jewelbug-crypto-fraud-espionage"},{"credibility":2,"name":"Jewelbug: A Single Control Panel for Cyberespionage and Fraud — Security Boulevard","type":"news_article","url":"https://securityboulevard.com/2026/08/jewelbug-a-single-control-panel-for-cyberespionage-and-fraud/"},{"credibility":2,"name":"China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"}]},{"content":"Jewelbug's financial arm operates an SEO poisoning campaign targeting Chinese-speaking cryptocurrency users. The group allegedly registered hundreds of lookalike domains impersonating the OKX and Binance exchanges, supported by more than 40 content management servers and click-fraud bots engineered to inflate search engine rankings for the fraudulent pages. The fake exchange pages are generated using artificial intelligence tools and include evasion logic: click-fraud bots serve harmless content to automated scanners and security crawlers while funneling real human visitors to the malicious lure pages. Victims searching for OKX or Binance downloads are directed to these pages and prompted to either download a trojanized desktop client or install the malicious 'PDF Viewer' browser extension. The infrastructure for the fraud arm was registered under a company in Hunan Province that advertised search-engine optimization services on Telegram, according to Symantec. The operator handle 'paopaodada' was found reused as the administrator credential across the CMS fleet. Decoy documents impersonating Taiwanese government entities also appeared in the group's infrastructure, suggesting Taiwan-based targeting as well.","heading":"Cryptocurrency Fraud Operations","severity":"critical","sources":[{"credibility":2,"name":"Jewelbug crypto fraud exposed: 580,000 stolen cookies behind fake exchanges — The Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/08/13/jewelbug-crypto-fraud-exposed/"},{"credibility":2,"name":"Jewelbug runs espionage and cryptocurrency fraud operations, says Symantec — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/jewelbug-espionage-crypto-fraud-symantec/"},{"credibility":2,"name":"Jewelbug APT: China-Based Govt Espionage and Crypto Fraud Exposed — TechNadu","type":"news_article","url":"https://www.technadu.com/jewelbug-the-chinese-hacker-group-that-spies-on-governments-by-day-drains-crypto-wallets-by-night/633188/"}]},{"content":"A central tool in Jewelbug's crypto fraud campaign is a malicious browser extension distributed under the name 'PDF Viewer,' available for both Chrome and Firefox. The extension requests a wide set of dangerous permissions, including cookie access, debugger control, web request interception, and JavaScript injection capabilities. Once installed, it harvests browser cookies, session tokens, credentials, browsing history, bookmarks, screenshots, and clipboard contents. A native Windows messaging helper component accompanying the extension enables operators to execute system-level commands via the Windows command interpreter, effectively converting the browser into a full remote-access channel. Of particular concern to cryptocurrency users: the extension contains a built-in address-swapping feature that can silently replace a victim's intended destination wallet address with an attacker-controlled address at the moment of a transaction, without any visible indication to the user. According to TechNadu's reporting on the Symantec findings, Symantec found no confirmed evidence that this address-swapping capability had been actively deployed against victims during the observed investigation period; however, the feature was present and functional in analyzed samples. The extension's evasion design checks VirusTotal signatures on a 12-hour cycle to rotate infrastructure before detection signatures propagate.","heading":"Malicious PDF Viewer Browser Extension","severity":"critical","sources":[{"credibility":2,"name":"Jewelbug APT: China-Based Govt Espionage and Crypto Fraud Exposed — TechNadu","type":"news_article","url":"https://www.technadu.com/jewelbug-the-chinese-hacker-group-that-spies-on-governments-by-day-drains-crypto-wallets-by-night/633188/"},{"credibility":1,"name":"Jewelbug APT Group Runs Espionage and Crypto Fraud Operations Side by Side — Security.com (Symantec/Broadcom)","type":"research","url":"https://www.security.com/threat-intelligence/jewelbug-crypto-fraud-espionage"},{"credibility":2,"name":"Jewelbug runs espionage and cryptocurrency fraud operations, says Symantec — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/jewelbug-espionage-crypto-fraud-symantec/"}]},{"content":"Symantec's analysis of Jewelbug's victim database revealed the following recorded figures: more than one million implant check-in rows; more than 580,000 stolen browser cookies; several thousand captured credentials; and more than 2,300 exfiltrated email bodies. The group's geolocation telemetry logged approximately 1.1 million events across approximately 4,300 distinct IP addresses. Connection data showed roughly 87,200 connections originating from a Southeast Asian nation's state telecommunications and military networks; approximately 53,100 from a Middle Eastern country including national carrier ranges and Starlink-connected addresses; and approximately 15,000 from another Southeast Asian nation's government ministry infrastructure. The 580,000-cookie figure was recorded within a three-month window according to reporting by Security.com.","heading":"Scale of Data Theft","severity":"critical","sources":[{"credibility":1,"name":"Jewelbug APT Group Runs Espionage and Crypto Fraud Operations Side by Side — Security.com (Symantec/Broadcom)","type":"research","url":"https://www.security.com/threat-intelligence/jewelbug-crypto-fraud-espionage"},{"credibility":2,"name":"Jewelbug Spy Ring Hit 15 Ministries in One Strike, Ran Crypto Fraud From Same Panel — TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/324587/20260815/jewelbug-spy-ring-hit-15-ministries-one-strike-ran-crypto-fraud-same-panel.htm"},{"credibility":2,"name":"Jewelbug crypto fraud exposed: 580,000 stolen cookies behind fake exchanges — The Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/08/13/jewelbug-crypto-fraud-exposed/"}]},{"content":"Jewelbug's state-sponsored espionage arm targeted government ministries across the Middle East, Southeast Asia, South Asia, and reportedly Taiwan. In its largest documented campaign wave, the group compromised a shared web-hosting platform operated by a state telecommunications and network services provider, gaining write access to the hosting environment and planting a malicious JavaScript payload that propagated across more than 15 government webmail tenants simultaneously. The injected payload exfiltrated browser cookies over WebSocket connections and delivered fake Adobe Flash update prompts to lure additional malware installation. Targets identified by Symantec include navy, police, and army intelligence bodies in Southeast Asia. The group's custom malware includes Antino, a Windows backdoor delivered through malicious HTML Application files and fake Adobe installer prompts that uses the Microsoft Graph API as its command-and-control channel to blend with legitimate cloud traffic; and ClientKing, a Rust-based implant targeting Linux servers and network devices, supporting DNS tunneling, interactive shells, SOCKS proxying, and in-memory kernel module loading. Fifty-seven variants of ClientKing were observed, some configured to route traffic through U.S. aerospace manufacturer proxy infrastructure. In October 2025, the group was separately attributed to a five-month intrusion targeting a Russian IT service provider to deliver malware designed to interfere with security tool functionality.","heading":"Espionage Operations Against Government Ministries","severity":"high","sources":[{"credibility":2,"name":"Hackers breach govt webmail while running parallel crypto fraud — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/hackers-breach-govt-webmail-while-running-parallel-crypto-fraud/"},{"credibility":1,"name":"Jewelbug APT Group Runs Espionage and Crypto Fraud Operations Side by Side — Security.com (Symantec/Broadcom)","type":"research","url":"https://www.security.com/threat-intelligence/jewelbug-crypto-fraud-espionage"},{"credibility":2,"name":"Researchers Link Suspected Chinese APT to Hack-for-Hire Operations — Infosecurity Magazine","type":"news_article","url":"https://www.infosecurity-magazine.com/news/researchers-link-chinese-apt-hack/"}]},{"content":"Jewelbug's cryptocurrency fraud infrastructure presents a direct, active threat to retail cryptocurrency users, particularly Chinese-speaking users of the OKX and Binance platforms. The group's SEO poisoning campaigns place malicious fake-exchange download pages at high positions in search results, meaning users searching for official exchange software may encounter fraudulent lure pages before legitimate ones. The malicious 'PDF Viewer' extension, once installed, provides persistent access to all browser activity including live session cookies, which can be used to access exchange accounts even if a victim changes their password. The wallet address-swapping capability embedded in the extension means that even a user who identifies the correct wallet address before initiating a transaction could have that address silently replaced at the moment of sending. No total financial losses to crypto victims have been publicly quantified by Symantec or other researchers as of August 2026, and Symantec's report stated that no confirmed deployment of the address-swapping feature was observed during the investigation period.","heading":"Threat to Retail Cryptocurrency Users","severity":"critical","sources":[{"credibility":2,"name":"Jewelbug APT Hijacks Browsers to Steal Cookies and Spy on Government Networks — CyberSecurityNews","type":"news_article","url":"https://cybersecuritynews.com/jewelbug-apt-hijacks-browsers/"},{"credibility":2,"name":"China-linked Jewelbug group conducts espionage and cryptocurrency theft — SC Media","type":"news_article","url":"https://www.scworld.com/brief/china-linked-jewelbug-group-conducts-espionage-and-cryptocurrency-theft"},{"credibility":2,"name":"Jewelbug runs espionage and cryptocurrency fraud operations, says Symantec — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/jewelbug-espionage-crypto-fraud-symantec/"}]},{"content":"As of August 16, 2026, no law enforcement action, criminal indictment, arrest, extradition request, or sanctions designation targeting Jewelbug or its identified operators has been publicly announced by any government. The group's alleged base in Hunan Province, China, places its primary operators outside the practical reach of Western law enforcement absent diplomatic cooperation with Chinese authorities. Symantec's report identified one operator by name, handle, and corporate affiliation, but no corresponding law enforcement referral outcome has been publicly reported. The absence of action is consistent with the broader pattern for China-based APT groups, where technical attribution by private researchers has not historically translated into criminal proceedings.","heading":"Law Enforcement and Regulatory Status","severity":"medium","sources":[{"credibility":1,"name":"Jewelbug APT Group Runs Espionage and Crypto Fraud Operations Side by Side — Security.com (Symantec/Broadcom)","type":"research","url":"https://www.security.com/threat-intelligence/jewelbug-crypto-fraud-espionage"},{"credibility":2,"name":"'Jewelbug' APT Balances State Espionage and Cryptocurrency Theft — Dark Reading","type":"news_article","url":"https://www.darkreading.com/threat-intelligence/jewelbug-apt-state-espionage-cryptocurrency-theft"}]}],"sources_used":[{"credibility":1,"name":"Jewelbug APT Group Runs Espionage and Crypto Fraud Operations Side by Side — Security.com (Symantec/Broadcom)","type":"research","url":"https://www.security.com/threat-intelligence/jewelbug-crypto-fraud-espionage"},{"credibility":2,"name":"Hackers breach govt webmail while running parallel crypto fraud — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/hackers-breach-govt-webmail-while-running-parallel-crypto-fraud/"},{"credibility":2,"name":"China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"},{"credibility":2,"name":"Jewelbug runs espionage and cryptocurrency fraud operations, says Symantec — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/jewelbug-espionage-crypto-fraud-symantec/"},{"credibility":2,"name":"Jewelbug crypto fraud exposed: 580,000 stolen cookies behind fake exchanges — The Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/08/13/jewelbug-crypto-fraud-exposed/"},{"credibility":2,"name":"Jewelbug APT: China-Based Govt Espionage and Crypto Fraud Exposed — TechNadu","type":"news_article","url":"https://www.technadu.com/jewelbug-the-chinese-hacker-group-that-spies-on-governments-by-day-drains-crypto-wallets-by-night/633188/"},{"credibility":2,"name":"Jewelbug Spy Ring Hit 15 Ministries in One Strike, Ran Crypto Fraud From Same Panel — TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/324587/20260815/jewelbug-spy-ring-hit-15-ministries-one-strike-ran-crypto-fraud-same-panel.htm"},{"credibility":2,"name":"China-linked Jewelbug group conducts espionage and cryptocurrency theft — SC Media","type":"news_article","url":"https://www.scworld.com/brief/china-linked-jewelbug-group-conducts-espionage-and-cryptocurrency-theft"},{"credibility":2,"name":"Jewelbug: A Single Control Panel for Cyberespionage and Fraud — Security Boulevard","type":"news_article","url":"https://securityboulevard.com/2026/08/jewelbug-a-single-control-panel-for-cyberespionage-and-fraud/"},{"credibility":2,"name":"'Jewelbug' APT Balances State Espionage and Cryptocurrency Theft — Dark Reading","type":"news_article","url":"https://www.darkreading.com/threat-intelligence/jewelbug-apt-state-espionage-cryptocurrency-theft"},{"credibility":2,"name":"Jewelbug APT Hijacks Browsers to Steal Cookies and Spy on Government Networks — CyberSecurityNews","type":"news_article","url":"https://cybersecuritynews.com/jewelbug-apt-hijacks-browsers/"},{"credibility":2,"name":"Researchers Link Suspected Chinese APT to Hack-for-Hire Operations — Infosecurity Magazine","type":"news_article","url":"https://www.infosecurity-magazine.com/news/researchers-link-chinese-apt-hack/"}],"summary":"Jewelbug is a China-based advanced persistent threat group, also tracked as Earth Alux, REF7707, and CL-STA-0049, that simultaneously conducts state-sponsored espionage against government ministries and a parallel cryptocurrency fraud operation from shared infrastructure. Symantec's Threat Hunter Team (a Broadcom division) published its attribution report on August 13, 2026, documenting over 580,000 stolen browser cookies, more than 2,300 exfiltrated email bodies, and a malicious browser extension capable of silently swapping cryptocurrency wallet addresses at transaction time. No law enforcement action against the group had been announced as of August 2026.","timeline":[{"date":"2013-01-01","event":"Earliest malware samples linked to Jewelbug infrastructure traced to this period, per Symantec analysis.","source":"Security.com (Symantec/Broadcom)","source_url":"https://www.security.com/threat-intelligence/jewelbug-crypto-fraud-espionage"},{"date":"2023-04-01","event":"Sustained operational activity confirmed from at least Q2 2023, including espionage and cryptocurrency fraud campaigns.","source":"Crypto Briefing","source_url":"https://cryptobriefing.com/jewelbug-espionage-crypto-fraud-symantec/"},{"date":"2025-10-01","event":"Group attributed to a five-month intrusion targeting a Russian IT service provider to deliver malware interfering with security tool functionality.","source":"The Hacker News","source_url":"https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"},{"date":"2026-08-13","event":"Symantec's Threat Hunter Team (Broadcom) publishes full attribution report on Jewelbug, disclosing dual espionage and cryptocurrency fraud operations, XG-Web infrastructure details, malware arsenal, operator identity linked to Hunan Province company, and scale of 580,000+ stolen cookies.","source":"Security.com (Symantec/Broadcom)","source_url":"https://www.security.com/threat-intelligence/jewelbug-crypto-fraud-espionage"},{"date":"2026-08-13","event":"BleepingComputer, The Hacker News, Crypto Briefing, The Cryptonomist, SC Media, and Infosecurity Magazine publish coverage of the Symantec Jewelbug attribution report.","source":"BleepingComputer","source_url":"https://www.bleepingcomputer.com/news/security/hackers-breach-govt-webmail-while-running-parallel-crypto-fraud/"},{"date":"2026-08-15","event":"TechTimes and TechNadu publish follow-up analysis of the 15-ministry government webmail compromise and the shared XG-Web panel infrastructure.","source":"TechTimes","source_url":"https://www.techtimes.com/articles/324587/20260815/jewelbug-spy-ring-hit-15-ministries-one-strike-ran-crypto-fraud-same-panel.htm"},{"date":"2026-08-16","event":"No law enforcement action, sanctions designation, or indictment against Jewelbug operators confirmed as of this date.","source":"AVOID.NET research compilation","source_url":"https://www.avoid.net"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision bb4d007f-c5ad-4a75-854d-45cf8640ed47
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.